[Pkg-javascript-devel] Processing of node-iconv_2.3.5-4_sourceonly.changes

2020-06-19 Thread Debian FTP Masters
node-iconv_2.3.5-4_sourceonly.changes uploaded successfully to localhost along with the files: node-iconv_2.3.5-4.dsc node-iconv_2.3.5-4.debian.tar.xz Greetings, Your Debian queue daemon (running on host usper.debian.org) -- Pkg-javascript-devel mailing list Pkg-javascript-devel@ali

[Pkg-javascript-devel] Processed: Bug#963039 marked as pending in node-iconv

2020-06-19 Thread Debian Bug Tracking System
Processing control commands: > tag -1 pending Bug #963039 [src:node-iconv] node-iconv: versions of nodejs dependencies not properly documented Added tag(s) pending. -- 963039: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=963039 Debian Bug Tracking System Contact ow...@bugs.debian.org with

[Pkg-javascript-devel] Bug#963149: marked as done (node-elliptic: CVE-2020-13822)

2020-06-19 Thread Debian Bug Tracking System
Your message dated Fri, 19 Jun 2020 18:05:44 + with message-id and subject line Bug#963149: fixed in node-elliptic 6.5.3~dfsg-1 has caused the Debian Bug report #963149, regarding node-elliptic: CVE-2020-13822 to be marked as done. This means that you claim that the problem has been dealt wit

[Pkg-javascript-devel] node-elliptic_6.5.3~dfsg-1_source.changes ACCEPTED into unstable

2020-06-19 Thread Debian FTP Masters
Accepted: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Fri, 19 Jun 2020 19:34:40 +0200 Source: node-elliptic Architecture: source Version: 6.5.3~dfsg-1 Distribution: unstable Urgency: high Maintainer: Debian Javascript Maintainers Changed-By: Jonas Smedegaard Closes: 963

[Pkg-javascript-devel] nodejs_14.4.0~dfsg-1_ppc64el.changes ACCEPTED into experimental, experimental

2020-06-19 Thread Debian FTP Masters
Accepted: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Thu, 11 Jun 2020 23:11:59 +0200 Source: nodejs Binary: libnode-dev libnode83 libnode83-dbgsym nodejs nodejs-dbgsym nodejs-doc Architecture: source ppc64el all Version: 14.4.0~dfsg-1 Distribution: experimental Urgency: m

[Pkg-javascript-devel] nodejs_14.4.0~dfsg-2_ppc64el.changes ACCEPTED into experimental, experimental

2020-06-19 Thread Debian FTP Masters
Accepted: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Sun, 14 Jun 2020 16:59:47 +0200 Source: nodejs Binary: libnode-dev libnode83 libnode83-dbgsym nodejs nodejs-dbgsym nodejs-doc Architecture: source ppc64el all Version: 14.4.0~dfsg-2 Distribution: experimental Urgency: m

[Pkg-javascript-devel] Processing of node-elliptic_6.5.3~dfsg-1_source.changes

2020-06-19 Thread Debian FTP Masters
node-elliptic_6.5.3~dfsg-1_source.changes uploaded successfully to localhost along with the files: node-elliptic_6.5.3~dfsg-1.dsc node-elliptic_6.5.3~dfsg.orig.tar.xz node-elliptic_6.5.3~dfsg-1.debian.tar.xz node-elliptic_6.5.3~dfsg-1_amd64.buildinfo Greetings, Your Debian queue d

[Pkg-javascript-devel] Bug#963039: Bug#963039: node-iconv: versions of nodejs dependencies not properly documented

2020-06-19 Thread Paul Gevers
Hi Jérémy and Xavier, On 19/06/2020 13.33, Jérémy Lal wrote: > libnode68 and libnode72 can be co-installed. Sure. > /usr/bin/node is going to load the lib with the SONAME it's been built for. Of course, like any normal binary that is linked against a library in Debian. > So of course nodejs 12

[Pkg-javascript-devel] Bug#963149: node-elliptic: CVE-2020-13822

2020-06-19 Thread Salvatore Bonaccorso
Source: node-elliptic Version: 6.5.1~dfsg-2 Severity: important Tags: security upstream Forwarded: https://github.com/indutny/elliptic/issues/226 Hi, The following vulnerability was published for node-elliptic. CVE-2020-13822[0]: | The Elliptic package 6.5.2 for Node.js allows ECDSA signature |

[Pkg-javascript-devel] Bug#963039: Bug#963039: node-iconv: versions of nodejs dependencies not properly documented

2020-06-19 Thread Paul Gevers
Hi Xavier, On 19/06/2020 08.07, Xavier wrote: > could we solve this by adding a: > > Breaks: nodejs (<< ${binary::Version}~) > > in libnode72 package ? If it works, this will solve the problem for all > similar packages. Are you proposing a solution to the current issue, or is this your long