Processing commands for cont...@bugs.debian.org:
> tags 1040592 + upstream
Bug #1040592 [src:node-dottie] node-dottie: CVE-2023-26132
Added tag(s) upstream.
> found 1040592 2.0.2-1
Bug #1040592 [src:node-dottie] node-dottie: CVE-2023-26132
Marked as found in versions node-dottie/2.0.2-1.
> thanks
Thank you for your contribution to Debian.
Accepted:
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512
Format: 1.8
Date: Sat, 08 Jul 2023 06:47:05 +0400
Source: node-tough-cookie
Architecture: source
Version: 4.1.3+~4.0.2-2
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Mai
node-tough-cookie_4.1.3+~4.0.2-2_sourceonly.changes uploaded successfully to
localhost
along with the files:
node-tough-cookie_4.1.3+~4.0.2-2.dsc
node-tough-cookie_4.1.3+~4.0.2-2.debian.tar.xz
Greetings,
Your Debian queue daemon (running on host usper.debian.org)
--
Pkg-javascript-
Source: node-dottie
X-Debbugs-CC: t...@security.debian.org
Severity: important
Tags: security
Hi,
The following vulnerability was published for node-dottie.
CVE-2023-26132[0]:
| Versions of the package dottie before 2.0.4 are vulnerable to
| Prototype Pollution due to insufficient checks, via th
Package: seek-bzip
Version: 1.0.5-2
Severity: serious
User: debian...@lists.debian.org
Usertags: piuparts
Hi,
during a test with piuparts I noticed your package ships (or creates)
broken symlinks:
0m22.5s ERROR: FAIL: Broken symlinks:
/usr/bin/seek-bunzip -> ../share/nodejs/@openpgp/seek-bzip/
Package: release.debian.org
Severity: normal
Tags: bookworm
User: release.debian@packages.debian.org
Usertags: pu
X-Debbugs-Cc: node-tough-coo...@packages.debian.org
Control: affects -1 + src:node-tough-cookie
[ Reason ]
node-tough-cookie is vulnerable to prototype pollution
[ Impact ]
Littel
Thank you for your contribution to Debian.
Accepted:
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512
Format: 1.8
Date: Fri, 07 Jul 2023 16:05:05 +0400
Source: node-tough-cookie
Built-For-Profiles: nocheck
Architecture: source
Version: 4.1.3+~4.0.2-1
Distribution: unstable
Urgency: medium
Maint
node-tough-cookie_4.1.3+~4.0.2-1_sourceonly.changes uploaded successfully to
localhost
along with the files:
node-tough-cookie_4.1.3+~4.0.2-1.dsc
node-tough-cookie_4.1.3+~4.0.2.orig-typestough-cookie.tar.xz
node-tough-cookie_4.1.3+~4.0.2.orig.tar.xz
node-tough-cookie_4.1.3+~4.0.2-1.debian.