Re: open security issues in the git packages

2023-01-19 Thread Jeremy Stanley
On 2023-01-19 14:04:52 + (+), Jeremy Stanley wrote: [...] > The only patch my colleagues and I found which needed adjustment > was 0012, and for that I was able to apply upstream commit 3c50032 > directly instead. Ubuntu has issued https://ubuntu.com/security/notices/USN-5810-2 now coverin

Re: open security issues in the git packages

2023-01-19 Thread Jeremy Stanley
On 2023-01-18 23:34:37 + (UTC), Thorsten Glaser wrote: [...] > The versions in Debian and *buntu don’t exactly match, but perhaps > appropriate patches for the respective versions are available, or > they apply with little fuzz? [...] Just a data point around this, I spent a good chunk of yest

open security issues in the git packages

2023-01-18 Thread Thorsten Glaser
Hi Jonathan, are you planning to fix the open security issues in git? In addition to the two new ones from… last week I think, given Ubuntu LTS-security has been carrying the fixes for 8 days now, there’s another four issues in stable that are fixed in testing/sid (newer versions?) and oldstable (