[Pkg-javascript-devel] Bug#1078880: Bug#1078880: gettext.js: CVE-2024-43370

2024-08-20 Thread Salvatore Bonaccorso
Hi Xavier, On Tue, Aug 20, 2024 at 05:33:49PM +0400, Yadd wrote: > On 8/20/24 17:30, Salvatore Bonaccorso wrote: > > Hi, > > > > On Tue, Aug 20, 2024 at 05:20:38PM +0400, Yadd wrote: > > > On 8/20/24 16:34, Moritz M??hlenhoff wrote: > > > > Hi Yadd, > > > > > > > > > here is a simple patch for t

[Pkg-javascript-devel] node-cliui 7.0.4+repack+1+~cs1.4.2-2 MIGRATED to testing

2024-08-20 Thread Debian testing watch
FYI: The status of the node-cliui source package in Debian's testing distribution has changed. Previous version: 7.0.4+repack+~cs3.1.0-4 Current version: 7.0.4+repack+1+~cs1.4.2-2 -- This email is automatically generated once a day. As the installation of new packages into testing happens

[Pkg-javascript-devel] node-mocha 10.7.2+ds1+~cs33.1.11-2 MIGRATED to testing

2024-08-20 Thread Debian testing watch
FYI: The status of the node-mocha source package in Debian's testing distribution has changed. Previous version: 10.4.0+ds1+~cs33.1.8-1 Current version: 10.7.2+ds1+~cs33.1.11-2 -- This email is automatically generated once a day. As the installation of new packages into testing happens mul

[Pkg-javascript-devel] node-tap 16.3.7+ds3+~cs49.5.20-1 MIGRATED to testing

2024-08-20 Thread Debian testing watch
FYI: The status of the node-tap source package in Debian's testing distribution has changed. Previous version: 16.3.7+ds1+~cs50.9.19-7 Current version: 16.3.7+ds3+~cs49.5.20-1 -- This email is automatically generated once a day. As the installation of new packages into testing happens mult

[Pkg-javascript-devel] node-path-scurry 1.9.2-2 MIGRATED to testing

2024-08-20 Thread Debian testing watch
FYI: The status of the node-path-scurry source package in Debian's testing distribution has changed. Previous version: (not in testing) Current version: 1.9.2-2 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a da

[Pkg-javascript-devel] Bug#1078880: Bug#1078880: gettext.js: CVE-2024-43370

2024-08-20 Thread Yadd
On 8/20/24 17:30, Salvatore Bonaccorso wrote: Hi, On Tue, Aug 20, 2024 at 05:20:38PM +0400, Yadd wrote: On 8/20/24 16:34, Moritz M??hlenhoff wrote: Hi Yadd, here is a simple patch for this issue The debdiff looks fine, but I don't believe this needs a DSA, can you please submit this for th

[Pkg-javascript-devel] Bug#1079144: bullseye-pu: package gettext.js/0.7.0-2+deb11u1

2024-08-20 Thread Yadd
Package: release.debian.org Severity: normal Tags: bullseye X-Debbugs-Cc: gettext...@packages.debian.org, y...@debian.org Control: affects -1 + src:gettext.js User: release.debian@packages.debian.org Usertags: pu [ Reason ] gettext is vulnerable to a SSRF issue (#1078880, CVE-2024-43370) [ Im

[Pkg-javascript-devel] Bug#1079143: bookworm-pu: package gettext.js/0.7.0-3+deb12u1

2024-08-20 Thread Yadd
Package: release.debian.org Severity: normal Tags: bookworm X-Debbugs-Cc: gettext...@packages.debian.org, y...@debian.org Control: affects -1 + src:gettext.js User: release.debian@packages.debian.org Usertags: pu [ Reason ] gettext is vulnerable to a SSRF issue (#1078880, CVE-2024-43370) [ Im

[Pkg-javascript-devel] Bug#1078880: Bug#1078880: gettext.js: CVE-2024-43370

2024-08-20 Thread Yadd
On 8/20/24 16:34, Moritz Mühlenhoff wrote: Hi Yadd, here is a simple patch for this issue The debdiff looks fine, but I don't believe this needs a DSA, can you please submit this for the next point update instead? Agree, but the bug was tagged as "grave" ;-) Cheers, Xavier -- Pkg-javascri

[Pkg-javascript-devel] Bug#1078880: Bug#1078880: gettext.js: CVE-2024-43370

2024-08-20 Thread Moritz Mühlenhoff
Hi Yadd, > here is a simple patch for this issue The debdiff looks fine, but I don't believe this needs a DSA, can you please submit this for the next point update instead? Cheers, Moritz -- Pkg-javascript-devel mailing list Pkg-javascript-devel@alioth-lists.debian.net https://alioth-l