Re: RM: ckeditor3 -- NVIU; specific to php-horde, EOL'd upstream, unfixed security issues

2025-04-04 Thread Sylvain Beucler
Update: virtuoso-opensource dropped ckeditor3: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1101019 (removed the related binary package entirely) ckeditor3 is now unused: $ dak rm -Rn ckeditor3 ... No dependency problem found. Cheers! Sylvain

Re: Support for ckeditor3 in Debian

2025-04-04 Thread Sylvain Beucler
Hello Security Team, On 21/03/2025 22:53, Sylvain Beucler wrote: On 12/08/2024 02:27, Mike Gabriel wrote: On  So 11 Aug 2024 12:57:23 CEST, Moritz Muehlenhoff wrote: On Sat, Aug 10, 2024 at 11:19:24AM -0300, Santiago Ruano Rincón wrote: El 31/05/22 a las 05:42, Mike Gabriel escribió: > On  Mo

Re: bson CVEs in (E)LTS

2025-04-04 Thread Roberto C . Sánchez
On Mon, Mar 31, 2025 at 04:20:08PM +0100, Chris Lamb wrote: > Adrian Bunk wrote: > > > It would make sense if the same person fixes the CVEs in all copies of > > the bson code in all releases. > > Indeed it would. If someone has a connection or history with any of > these packages already, I'd b

Debian LTS and ELTS - March 2025

2025-04-04 Thread Sylvain Beucler
Here is my public monthly report. Thanks to our sponsors for making this possible, and to Freexian for handling the offering. https://www.freexian.com/lts/debian/#sponsors LTS - openvpn review - Continue reviewing proposed update by @aquilamacedo https://salsa.debian.org/debian/openvpn/-/