Hi Vincent, * Vincent Danjean <[EMAIL PROTECTED]> [2008-10-04 12:16]: > Martin Geisler wrote: [...] > >> But when I look at the Debian site: > >> http://packages.debian.org/etch/mercurial it lists mercurial > >> (0.9.1-1+etch1) which implies an even older version than Ubuntu. > > > > The current stable Debian release is etch, and this was released in > > April 2007. The next stable release (the "testing" distribution called > > lenny) will contain 1.0.1: > > Unless big security bugs, Debian packages of the stable release are never > updated. Currently, the stable release is etch. The next one, lenny, is in > preparation. It will have mercurial 1.0.1 because 1.0.2 has been released > after the freeze (ie near a release, packages cannot be updated in Debian > unless security bug. And only patch for this bug can be backported) > > Hint: if anyone can point me to a specific changeset to fix the second > security bug fixed in 1.0.2 ("Mercurial before 1.0.2 does not enforce the > allowpull permission"), I will backport it to 1.0.1 in the next Debian > release (see http://bugs.debian.org/500781 )
Errm did you see the patch I already posted to this bug? http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=500781#22 Cheers Nico -- Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13 encrypted.
pgpWqsbV2G19U.pgp
Description: PGP signature