Re: 11.8/12.2 planning

2023-07-24 Thread Donald Norwood
On 7/24/23 14:25, Jonathan Wiltshire wrote: I think I confused matters with my messy thread; let's start again. I originally suggested: Jonathan Wiltshire (2023-06-28): The proper cadence for 11.8 and 12.2 is the weekend of 30th September 2023. Please indicate your availability for: 23 Sep

Bug#1041854: bookworm-pu: package calibre/6.13.0+repack-2+deb12u1

2023-07-24 Thread yokota
> Please go ahead. Thank you, I uploaded the fixed package. -- YOKOTA Hiroshi

NEW changes in oldstable-new

2023-07-24 Thread Debian FTP Masters
Processing changes file: hnswlib_0.4.0-3+deb11u1_all-buildd.changes ACCEPT Processing changes file: hnswlib_0.4.0-3+deb11u1_amd64-buildd.changes ACCEPT Processing changes file: hnswlib_0.4.0-3+deb11u1_arm64-buildd.changes ACCEPT Processing changes file: hnswlib_0.4.0-3+deb11u1_armel-buildd.ch

Bug#1040679: bullseye-pu: package node-dottie/2.0.2-4+deb11u1

2023-07-24 Thread Adam D. Barratt
On Mon, 2023-07-24 at 21:27 +0100, Jonathan Wiltshire wrote: > Control: tag -1 confirmed > > On Sun, Jul 09, 2023 at 09:11:26AM +0400, Yadd wrote: > > [ Reason ] > > node-dottie is vulnerable to prototype pollution (#1040592, > > CVE-2023-26132) > > By all means go ahead, but it can't be accepted

Re: 11.8/12.2 planning

2023-07-24 Thread Mark Hymers
On Mon, 24, Jul, 2023 at 07:25:13PM +0100, Jonathan Wiltshire spoke thus.. > Let's say 30 Sep is still preferred, 7th Oct or at a stretch 14th Oct are > options. Please indicate your availability for those three. I can do any of the above for ftp. Mark -- Mark Hymers signature.asc Descripti

Processed: Re: Bug#1039708: bullseye-pu: package lua5.3/5.3.3-1.1+deb11u1

2023-07-24 Thread Debian Bug Tracking System
Processing control commands: > tag -1 confirmed Bug #1039708 [release.debian.org] bullseye-pu: package lua5.3/5.3.3-1.1+deb11u1 Added tag(s) confirmed. -- 1039708: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1039708 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#1039708: bullseye-pu: package lua5.3/5.3.3-1.1+deb11u1

2023-07-24 Thread Jonathan Wiltshire
Control: tag -1 confirmed On Wed, Jun 28, 2023 at 02:22:21PM +0200, Guilhem Moulin wrote: > lua5.3=5.3.3-1.1 (buster, bullseye) is vulnerable to CVE-2019-6706 and > CVE-2020-24370. These were fixed in an a recent buster-security upload > (cf. DLA-3469-1). The Security Team didn't think a DSA was

Processed: Re: Bug#1040679: bullseye-pu: package node-dottie/2.0.2-4+deb11u1

2023-07-24 Thread Debian Bug Tracking System
Processing control commands: > tag -1 confirmed Bug #1040679 [release.debian.org] bullseye-pu: package node-dottie/2.0.2-4+deb11u1 Added tag(s) confirmed. -- 1040679: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1040679 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#1040679: bullseye-pu: package node-dottie/2.0.2-4+deb11u1

2023-07-24 Thread Jonathan Wiltshire
Control: tag -1 confirmed On Sun, Jul 09, 2023 at 09:11:26AM +0400, Yadd wrote: > [ Reason ] > node-dottie is vulnerable to prototype pollution (#1040592, > CVE-2023-26132) By all means go ahead, but it can't be accepted until the situation in testing is fixed up (unless we propogate the version

Bug#1040677: bullseye-pu: package node-tough-cookie/4.0.0-2+deb11u1

2023-07-24 Thread Jonathan Wiltshire
Control: tag -1 confirmed On Sun, Jul 09, 2023 at 08:34:39AM +0400, Yadd wrote: > [ Reason ] > node-tough-cookie is vulnerable to prototype pollution Please go ahead. Thanks, -- Jonathan Wiltshire j...@debian.org Debian Developer ht

Processed: Re: Bug#1040677: bullseye-pu: package node-tough-cookie/4.0.0-2+deb11u1

2023-07-24 Thread Debian Bug Tracking System
Processing control commands: > tag -1 confirmed Bug #1040677 [release.debian.org] bullseye-pu: package node-tough-cookie/4.0.0-2+deb11u1 Added tag(s) confirmed. -- 1040677: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1040677 Debian Bug Tracking System Contact ow...@bugs.debian.org with pr

Bug#1006294: bullseye-pu: package knewstuff/5.78.0-4

2023-07-24 Thread Jonathan Wiltshire
Control: tag -1 confirmed On Tue, Feb 22, 2022 at 10:48:45PM +0100, Patrick Franz wrote: > [ Reason ] > A bug in plasma-discover causes a Denial of Service attack > against the KDE servers. 3 packages needs to be patch to > mitigate the attack: knewstuff, plasma-desktop and > plasma-discover. > Th

Processed: Re: Bug#1006294: bullseye-pu: package knewstuff/5.78.0-4

2023-07-24 Thread Debian Bug Tracking System
Processing control commands: > tag -1 confirmed Bug #1006294 [release.debian.org] bullseye-pu: package knewstuff/5.78.0-4 Added tag(s) confirmed. -- 1006294: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1006294 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#1036811: bullseye-pu: package ncurses/6.2+20201114-2+deb11u2

2023-07-24 Thread Sven Joachim
On 2023-07-24 18:37 +0100, Jonathan Wiltshire wrote: > Control: tag -1 confirmed > > On Fri, May 26, 2023 at 08:51:55PM +0200, Sven Joachim wrote: >> I would like to address CVE-2023-29491[1] aka bug #1034372[2] in >> Bullseye. The changes are the same as in version 6.4-3 (see >> #1035351[3]), ex

11.8/12.2 planning

2023-07-24 Thread Jonathan Wiltshire
I think I confused matters with my messy thread; let's start again. I originally suggested: Jonathan Wiltshire (2023-06-28): > The proper cadence for 11.8 and 12.2 is the weekend of 30th September > 2023. Please indicate your availability for: > > 23 Sep > 30 Sep (preferred) > 7 Oct Let's say

Bug#1007787: bullseye-pu: package adduser/3.118

2023-07-24 Thread Jonathan Wiltshire
Control: tag -1 moreinfo On Wed, Mar 16, 2022 at 07:25:44PM +0100, Marc Haber wrote: > This is my first try to do a stable upload. Since adduser is a vital > package, but my time is rather limited at the moment, I would like to > know whether this fix is acceptable for stable before I prepare an >

Processed: Re: Bug#1013893: bullseye-pu: package rhonabwy/0.9.13-3+deb11u1

2023-07-24 Thread Debian Bug Tracking System
Processing control commands: > tag -1 confirmed Bug #1013893 [release.debian.org] bullseye-pu: package rhonabwy/0.9.13-3+deb11u1 Added tag(s) confirmed. -- 1013893: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1013893 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Processed: Re: Bug#1007787: bullseye-pu: package adduser/3.118

2023-07-24 Thread Debian Bug Tracking System
Processing control commands: > tag -1 moreinfo Bug #1007787 [release.debian.org] bullseye-pu: package adduser/3.118 Added tag(s) moreinfo. -- 1007787: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1007787 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#1013893: bullseye-pu: package rhonabwy/0.9.13-3+deb11u1

2023-07-24 Thread Jonathan Wiltshire
Control: tag -1 confirmed On Sun, Jun 26, 2022 at 05:36:42PM -0400, Nicolas Mora wrote: > [ Reason ] > Fix possible buffer overflow when decrypting forged jwe with invalid iv or > cypherkey Please go ahead, mentioning the CVE number in the changelog. Thanks, -- Jonathan Wiltshire

Bug#1036811: bullseye-pu: package ncurses/6.2+20201114-2+deb11u2

2023-07-24 Thread Jonathan Wiltshire
Control: tag -1 confirmed On Fri, May 26, 2023 at 08:51:55PM +0200, Sven Joachim wrote: > I would like to address CVE-2023-29491[1] aka bug #1034372[2] in > Bullseye. The changes are the same as in version 6.4-3 (see > #1035351[3]), except that there is no need to patch configure.in this > time.

Processed: Re: Bug#1036811: bullseye-pu: package ncurses/6.2+20201114-2+deb11u2

2023-07-24 Thread Debian Bug Tracking System
Processing control commands: > tag -1 confirmed Bug #1036811 [release.debian.org] bullseye-pu: package ncurses/6.2+20201114-2+deb11u2 Added tag(s) confirmed. -- 1036811: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1036811 Debian Bug Tracking System Contact ow...@bugs.debian.org with probl

Processed: retitle 1036145 to RM: varconf -- RoM; unstable upstream, unsuitable for Debian

2023-07-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > retitle 1036145 RM: varconf -- RoM; unstable upstream, unsuitable for Debian Bug #1036145 [release.debian.org] RM: varconf/bullseye -- ROM; unstable upstream, unsuitable for Debian Changed Bug title to 'RM: varconf -- RoM; unstable upstream, unsu

Processed: retitle 1036143 to RM: mercator -- RoM; unstable upstream, unsuitable for Debian

2023-07-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > retitle 1036143 RM: mercator -- RoM; unstable upstream, unsuitable for Debian Bug #1036143 [release.debian.org] RM: mercator/bullseye -- ROM; unstable upstream, unsuitable for Debian Changed Bug title to 'RM: mercator -- RoM; unstable upstream, u

Processed: retitle 1036146 to RM: wfmath -- RoM; unstable upstream, unsuitable for Debian

2023-07-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > retitle 1036146 RM: wfmath -- RoM; unstable upstream, unsuitable for Debian Bug #1036146 [release.debian.org] RM: wfmath/bullseye -- ROM; unstable upstream, unsuitable for Debian Changed Bug title to 'RM: wfmath -- RoM; unstable upstream, unsuita

Processed: retitle 1036142 to RM: libwfut -- RoM; unstable upstream, unsuitable for Debian

2023-07-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > retitle 1036142 RM: libwfut -- RoM; unstable upstream, unsuitable for Debian Bug #1036142 [release.debian.org] RM: libwfut/bullseye -- ROM; unstable upstream, unsuitable for Debian Changed Bug title to 'RM: libwfut -- RoM; unstable upstream, unsu

Processed: retitle 1036144 to RM: skstream -- RoM; unstable upstream, unsuitable for Debian

2023-07-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > retitle 1036144 RM: skstream -- RoM; unstable upstream, unsuitable for Debian Bug #1036144 [release.debian.org] RM: skstream/bullseye -- ROM; unstable upstream, unsuitable for Debian Changed Bug title to 'RM: skstream -- RoM; unstable upstream, u

Processed: retitle 1036139 to RM: atlas-cpp -- RoM

2023-07-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > retitle 1036139 RM: atlas-cpp -- RoM Bug #1036139 [release.debian.org] RM: atlas-cpp/bullseye -- ROM; unstable upstream, unsuitable for Debian Changed Bug title to 'RM: atlas-cpp -- RoM' from 'RM: atlas-cpp/bullseye -- ROM; unstable upstream, un

Processed: retitle 1036140 to RM: ember-media -- RoM; unstable upstream, unsuitable for Debian

2023-07-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > retitle 1036140 RM: ember-media -- RoM; unstable upstream, unsuitable for > Debian Bug #1036140 [release.debian.org] RM: ember-media/bullseye -- ROM; unstable upstream, unsuitable for Debian Changed Bug title to 'RM: ember-media -- RoM; unstable

Processed: retitle 1036141 to RM: eris -- RoM; unstable upstream, unsuitable for Debian

2023-07-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > retitle 1036141 RM: eris -- RoM; unstable upstream, unsuitable for Debian Bug #1036141 [release.debian.org] RM: eris/bullseye -- ROM; unstable upstream, unsuitable for Debian Changed Bug title to 'RM: eris -- RoM; unstable upstream, unsuitable fo

Processed: retitle 1036139 to RM: atlas-cpp -- RoM; unstable upstream, unsuitable for Debian

2023-07-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > retitle 1036139 RM: atlas-cpp -- RoM; unstable upstream, unsuitable for Debian Bug #1036139 [release.debian.org] RM: atlas-cpp -- RoM Changed Bug title to 'RM: atlas-cpp -- RoM; unstable upstream, unsuitable for Debian' from 'RM: atlas-cpp -- RoM

Bug#1037107: Acknowledgement (pre-unblock: bookworm-pu: mariadb/1:10.11.3-2/+deb12u1)

2023-07-24 Thread Otto Kekäläinen
Changes done and pending CI to validate that there are no unintended side effects: https://salsa.debian.org/mariadb-team/mariadb-server/-/merge_requests/52

Bug#1037107: Acknowledgement (pre-unblock: bookworm-pu: mariadb/1:10.11.3-2/+deb12u1)

2023-07-24 Thread Otto Kekäläinen
On Mon, 24 Jul 2023 at 09:33, Jonathan Wiltshire wrote: > > There are two lintian warnings: > > W: debhelper-but-no-misc-depends mariadb-server-10.5 > W: transitional-package-not-oldlibs-optional database/optional The version in unstable has intentionally no changes to ensure maximum time of test

NEW changes in oldstable-new

2023-07-24 Thread Debian FTP Masters
Processing changes file: hnswlib_0.4.0-3+deb11u1_source.changes ACCEPT Processing changes file: kscreenlocker_5.20.5-1+deb11u1_source.changes ACCEPT Processing changes file: spip_3.2.11-3+deb11u9_source.changes ACCEPT Processing changes file: yajl_2.1.0-3+deb11u2_source.changes ACCEPT

Processed: tagging 1036811

2023-07-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 1036811 - moreinfo Bug #1036811 [release.debian.org] bullseye-pu: package ncurses/6.2+20201114-2+deb11u2 Removed tag(s) moreinfo. > thanks Stopping processing here. Please contact me if you need assistance. -- 1036811: https://bugs.debian.

Bug#1037107: Acknowledgement (pre-unblock: bookworm-pu: mariadb/1:10.11.3-2/+deb12u1)

2023-07-24 Thread Jonathan Wiltshire
There are two lintian warnings: W: debhelper-but-no-misc-depends mariadb-server-10.5 W: transitional-package-not-oldlibs-optional database/optional We also have a lack of dbgsym packages, probably because of the maintainer upload of amd64 and all. I'd quite like to fix the second lintian warning

Processed: spip 3.2.11-3+deb11u9 flagged for acceptance

2023-07-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > package release.debian.org Limiting to bugs with field 'package' containing at least one of 'release.debian.org' Limit currently set to 'package':'release.debian.org' > tags 1040758 = bullseye pending Bug #1040758 [release.debian.org] bullseye-p

Processed: kscreenlocker 5.20.5-1+deb11u1 flagged for acceptance

2023-07-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > package release.debian.org Limiting to bugs with field 'package' containing at least one of 'release.debian.org' Limit currently set to 'package':'release.debian.org' > tags 1036240 = bullseye pending Bug #1036240 [release.debian.org] bullseye-p

Processed: Re: Bug#1041854: bookworm-pu: package calibre/6.13.0+repack-2+deb12u1

2023-07-24 Thread Debian Bug Tracking System
Processing control commands: > tag -1 confirmed Bug #1041854 [release.debian.org] bookworm-pu: package calibre/6.13.0+repack-2+deb12u1 Added tag(s) confirmed. -- 1041854: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1041854 Debian Bug Tracking System Contact ow...@bugs.debian.org with prob

Bug#1041854: bookworm-pu: package calibre/6.13.0+repack-2+deb12u1

2023-07-24 Thread Jonathan Wiltshire
Control: tag -1 confirmed On Mon, Jul 24, 2023 at 10:19:20PM +0900, YOKOTA Hiroshi wrote: > [ Impact ] > Preferences dialog won't work Please go ahead. Thanks, -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debi

Processed: yajl 2.1.0-3+deb11u2 flagged for acceptance

2023-07-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > package release.debian.org Limiting to bugs with field 'package' containing at least one of 'release.debian.org' Limit currently set to 'package':'release.debian.org' > tags 1040865 = bullseye pending Bug #1040865 [release.debian.org] bullseye-p

Bug#1041475: hnswlib 0.4.0-3+deb11u1 flagged for acceptance

2023-07-24 Thread Jonathan Wiltshire
package release.debian.org tags 1041475 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: hnswlib Version: 0.4.0-3+deb

Processed: hnswlib 0.4.0-3+deb11u1 flagged for acceptance

2023-07-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > package release.debian.org Limiting to bugs with field 'package' containing at least one of 'release.debian.org' Limit currently set to 'package':'release.debian.org' > tags 1041475 = bullseye pending Bug #1041475 [release.debian.org] bullseye-p

Bug#1040865: yajl 2.1.0-3+deb11u2 flagged for acceptance

2023-07-24 Thread Jonathan Wiltshire
package release.debian.org tags 1040865 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: yajl Version: 2.1.0-3+deb11u

Bug#1040758: spip 3.2.11-3+deb11u9 flagged for acceptance

2023-07-24 Thread Jonathan Wiltshire
package release.debian.org tags 1040758 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: spip Version: 3.2.11-3+deb11

Bug#1036240: kscreenlocker 5.20.5-1+deb11u1 flagged for acceptance

2023-07-24 Thread Jonathan Wiltshire
package release.debian.org tags 1036240 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: kscreenlocker Version: 5.20.

Bug#1041854: bookworm-pu: package calibre/6.13.0+repack-2+deb12u1

2023-07-24 Thread YOKOTA Hiroshi
Package: release.debian.org Severity: normal Tags: bookworm User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: cali...@packages.debian.org, yokota.h...@gmail.com Control: affects -1 + src:calibre [ Reason ] To fix Debian bug 1041779 https://bugs.debian.org/cgi-bin/bugreport.

Processed: bookworm-pu: package calibre/6.13.0+repack-2+deb12u1

2023-07-24 Thread Debian Bug Tracking System
Processing control commands: > affects -1 + src:calibre Bug #1041854 [release.debian.org] bookworm-pu: package calibre/6.13.0+repack-2+deb12u1 Added indication that 1041854 affects src:calibre -- 1041854: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1041854 Debian Bug Tracking System Conta

Processed: transition: pagmo

2023-07-24 Thread Debian Bug Tracking System
Processing control commands: > affects -1 + src:pagmo Bug #1041841 [release.debian.org] transition: pagmo Added indication that 1041841 affects src:pagmo -- 1041841: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1041841 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#1041841: transition: pagmo

2023-07-24 Thread Pierre Gruet
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: transition X-Debbugs-Cc: pa...@packages.debian.org Control: affects -1 + src:pagmo Dear Release Team, I would like to ask for a transition slot for pagmo. libpagmo9 has been accepted in experiment