Bug#1040679: bullseye-pu: package node-dottie/2.0.2-4+deb11u1

2023-10-08 Thread Yadd
On 10/8/23 16:10, Jonathan Wiltshire wrote: Hi, This request was approved but not uploaded in time for the previous point release (11.8). Should it be included in 11.9, or should this request be abandoned and closed? Sorry, I was travelling. I just pushed the update Thanks!

Bug#1040679: bullseye-pu: package node-dottie/2.0.2-4+deb11u1

2023-10-08 Thread Jonathan Wiltshire
Hi, This request was approved but not uploaded in time for the previous point release (11.8). Should it be included in 11.9, or should this request be abandoned and closed? -- Jonathan Wiltshire j...@debian.org Debian Developer http://

Processed: Re: Bug#1040679: bullseye-pu: package node-dottie/2.0.2-4+deb11u1

2023-07-30 Thread Debian Bug Tracking System
Processing control commands: > tag -1 confirmed Bug #1040679 [release.debian.org] bullseye-pu: package node-dottie/2.0.2-4+deb11u1 Added tag(s) confirmed. -- 1040679: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1040679 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#1040679: bullseye-pu: package node-dottie/2.0.2-4+deb11u1

2023-07-30 Thread Jonathan Wiltshire
Control: tag -1 confirmed On Wed, Jul 26, 2023 at 08:37:28AM +0400, Yadd wrote: > Sorry, here is the new debdiff Please go ahead. Thanks, -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0x

Bug#1040679: bullseye-pu: package node-dottie/2.0.2-4+deb11u1

2023-07-25 Thread Yadd
Control: tags -1 - moreinfo On 7/25/23 11:40, Jonathan Wiltshire wrote: Control: tag -1 = bullseye moreinfo On Mon, Jul 24, 2023 at 09:37:58PM +0100, Adam D. Barratt wrote: On Mon, 2023-07-24 at 21:27 +0100, Jonathan Wiltshire wrote: Control: tag -1 confirmed On Sun, Jul 09, 2023 at 09:11:26

Processed: Re: Bug#1040679: bullseye-pu: package node-dottie/2.0.2-4+deb11u1

2023-07-25 Thread Debian Bug Tracking System
Processing control commands: > tags -1 - moreinfo Bug #1040679 [release.debian.org] bullseye-pu: package node-dottie/2.0.2-4+deb11u1 Removed tag(s) moreinfo. -- 1040679: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1040679 Debian Bug Tracking System Contact ow...@bugs.debian.org with probl

Processed: Re: Bug#1040679: bullseye-pu: package node-dottie/2.0.2-4+deb11u1

2023-07-25 Thread Debian Bug Tracking System
Processing control commands: > tag -1 = bullseye moreinfo Bug #1040679 [release.debian.org] bullseye-pu: package node-dottie/2.0.2-4+deb11u1 Added tag(s) moreinfo; removed tag(s) confirmed. -- 1040679: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1040679 Debian Bug Tracking System Contact

Bug#1040679: bullseye-pu: package node-dottie/2.0.2-4+deb11u1

2023-07-25 Thread Jonathan Wiltshire
Control: tag -1 = bullseye moreinfo On Mon, Jul 24, 2023 at 09:37:58PM +0100, Adam D. Barratt wrote: > On Mon, 2023-07-24 at 21:27 +0100, Jonathan Wiltshire wrote: > > Control: tag -1 confirmed > > > > On Sun, Jul 09, 2023 at 09:11:26AM +0400, Yadd wrote: > > > [ Reason ] > > > node-dottie is vul

Bug#1040679: bullseye-pu: package node-dottie/2.0.2-4+deb11u1

2023-07-24 Thread Adam D. Barratt
On Mon, 2023-07-24 at 21:27 +0100, Jonathan Wiltshire wrote: > Control: tag -1 confirmed > > On Sun, Jul 09, 2023 at 09:11:26AM +0400, Yadd wrote: > > [ Reason ] > > node-dottie is vulnerable to prototype pollution (#1040592, > > CVE-2023-26132) > > By all means go ahead, but it can't be accepted

Processed: Re: Bug#1040679: bullseye-pu: package node-dottie/2.0.2-4+deb11u1

2023-07-24 Thread Debian Bug Tracking System
Processing control commands: > tag -1 confirmed Bug #1040679 [release.debian.org] bullseye-pu: package node-dottie/2.0.2-4+deb11u1 Added tag(s) confirmed. -- 1040679: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1040679 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#1040679: bullseye-pu: package node-dottie/2.0.2-4+deb11u1

2023-07-24 Thread Jonathan Wiltshire
Control: tag -1 confirmed On Sun, Jul 09, 2023 at 09:11:26AM +0400, Yadd wrote: > [ Reason ] > node-dottie is vulnerable to prototype pollution (#1040592, > CVE-2023-26132) By all means go ahead, but it can't be accepted until the situation in testing is fixed up (unless we propogate the version

Bug#1040679: bullseye-pu: package node-dottie/2.0.2-4+deb11u1

2023-07-08 Thread Yadd
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: node-dot...@packages.debian.org Control: affects -1 + src:node-dottie [ Reason ] node-dottie is vulnerable to prototype pollution (#1040592, CVE-2023-26132) [ Impact