Re: CVE-2024-7531/nss for debian/bullseye LTS

2024-10-15 Thread Arturo Borrero Gonzalez
On 10/15/24 16:58, Santiago Ruano Rincón wrote: Moreover, I do see the code introduced by that change as part of 2:3.61-1+deb11u3, that relate to HACL* AVX2 support for different crypto algorithms. Could you please give more details about why do you say bullseye doesn't contain the affected code

Re: Host header in HTTP/2 requests / RFC 7540 interpretation

2024-10-12 Thread Arturo Bernal
+1. Being strict. No need to flood the logs Arturo On Sat, Oct 12, 2024 at 3:14 PM Oleg Kalnichevski wrote: > On Sat, 2024-10-12 at 07:43 -0400, Gary Gregory wrote: > > I think the remaining decisions are: > > > > - whether we should log a warning (but not throw an exc

CVE-2024-7531/nss for debian/bullseye LTS

2024-10-12 Thread Arturo Borrero Gonzalez
Hi there, this email is to propose we mark the nss package in debian bullseye as not affected by CVE-2024-7531 [0]. The upstream patch is clearly identified [1], but debian/bullseye [2] just doesn't contain the affected code. We did a similar thing for debian/{jessie,stretch,buster} already

Re: Host header in HTTP/2 requests / RFC 7540 interpretation

2024-10-12 Thread Arturo Bernal
. Arturo On Sat, Oct 12, 2024 at 12:47 PM Oleg Kalnichevski wrote: > Folks > > Presently HttpCore HTTP/2 protocol handler treats HTTP/2 request > messages with a `Host` header as malformed. > > However I just recently discovered that Apache HTTPD happily sends us > push pr

write combining using virtio

2024-10-11 Thread Arturo Vivas
27;t state the same for Alibaba and virtio. I would be thankful for any help in this regard. Regards, Arturo

[jira] [Closed] (HTTPCLIENT-2322) Javadoc lists each class twice

2024-10-06 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2322?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Arturo Bernal closed HTTPCLIENT-2322. - Resolution: Fixed Since the duplicate class listings no longer appear, and the

[jira] [Commented] (HTTPCLIENT-2322) Javadoc lists each class twice

2024-10-06 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2322?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17887229#comment-17887229 ] Arturo Bernal commented on HTTPCLIENT-2322: --- [~michael-o] I believ

[jira] [Updated] (HTTPCLIENT-2343) Regression in setting USER_TOKEN context attribute in PoolingHttpClientConnectionManager

2024-10-03 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2343?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Arturo Bernal updated HTTPCLIENT-2343: -- Fix Version/s: (was: 5.4.1) Affects Version/s: (was: 5.4

[jira] [Comment Edited] (HTTPCLIENT-2343) Regression in setting USER_TOKEN context attribute in PoolingHttpClientConnectionManager

2024-10-03 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2343?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17886779#comment-17886779 ] Arturo Bernal edited comment on HTTPCLIENT-2343 at 10/3/24 8:0

[jira] [Closed] (HTTPCLIENT-2343) Regression in setting USER_TOKEN context attribute in PoolingHttpClientConnectionManager

2024-10-03 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2343?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Arturo Bernal closed HTTPCLIENT-2343. - Resolution: Won't Fix After thorough review and testing, it is clear tha

[jira] [Resolved] (HTTPCLIENT-2233) Metrics missing

2024-10-03 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2233?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Arturo Bernal resolved HTTPCLIENT-2233. --- Resolution: Fixed In master > Metrics miss

[jira] [Updated] (HTTPCLIENT-2233) Metrics missing

2024-10-03 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2233?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Arturo Bernal updated HTTPCLIENT-2233: -- Fix Version/s: 5.4-alpha1 > Metrics miss

[Cloud] Re: Request for my Cloud VPS project review

2024-09-30 Thread Arturo Borrero Gonzalez
On 9/30/24 02:57, Sulav K Shetri wrote: I had requested an new Cloud VPS project 6 days back and waiting for review or approval but it has been 6 days since my request but till now no one has reviewed it so I wanted to know when will be reviewed and this is the link of my request Request creati

Debian LTS & ELTS report -- September 2024

2024-09-29 Thread Arturo Borrero Gonzalez
Hello, This is my September 2024 monthly report for the Freexian LTS/ELTS [1] initiative. Many thanks to Freexian and sponsors [2] for providing this opportunity! LTS: I worked on the nss package for Debian Bullseye, with the following highlights: * briefly evaluated CVE-2023-5388, but t

[jira] [Resolved] (HTTPCLIENT-2159) Invalid handling of charset content type parameter

2024-09-29 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2159?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Arturo Bernal resolved HTTPCLIENT-2159. --- Fix Version/s: 5.4-alpha1 Resolution: Fixed In master > Inva

[jira] [Resolved] (HTTPCORE-769) Force close on connection when 408 is returned

2024-09-29 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCORE-769?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Arturo Bernal resolved HTTPCORE-769. Fix Version/s: 5.4-alpha1 (was: Stuck) Resolution: Fixed

Re: [VOTE][LAZY] Release HttpComponents Parent 14 based on RC1

2024-09-29 Thread Arturo Bernal
+1 Arturo On Thu, Sep 26, 2024 at 9:37 AM Oleg Kalnichevski wrote: > Please lazy vote on releasing HttpComponents Parent 14 based on RC1. > > The vote is open for the at least 72 hours, and only votes from > HttpComponents PMC members are binding. The vote passes if at least one

[dev-tech-crypto] about CVE-2024-6609 for nss 3.61 in Debian Bullseye

2024-09-25 Thread Arturo Borrero Gonzalez
Hi there, I'm interested in having a patch for CVE-2024-6609 available for the nss version we have in Debian Bullseye (nss 3.61). We have a note [0] that mentions this: === 8< === To address CVE in older versions of src:nss what is needed is to add the error handling code (confirmed by upstrea

[Git][security-tracker-team/security-tracker][master] LTS: claim nss in dla-needed.txt

2024-09-25 Thread @arturo
Arturo Borrero González pushed to branch master at Debian Security Tracker / security-tracker Commits: 5d6adf76 by Arturo Borrero Gonzalez at 2024-09-25T21:16:28+02:00 LTS: claim nss in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes

[jira] [Commented] (HTTPCLIENT-2344) HTTP/1.1 TLS Upgrade (RFC-2817) should not be default

2024-09-24 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2344?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17884346#comment-17884346 ] Arturo Bernal commented on HTTPCLIENT-2344: --- I still don’t see any i

[jira] [Commented] (HTTPCLIENT-2344) HTTP/1.1 TLS Upgrade (RFC-2817) should not be default

2024-09-24 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2344?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17884323#comment-17884323 ] Arturo Bernal commented on HTTPCLIENT-2344: --- IMO We should stri

[Git][security-tracker-team/security-tracker][master] CVE-2024-6609: bullseye: mark as fixed in nss > 3.61

2024-09-23 Thread @arturo
Arturo Borrero González pushed to branch master at Debian Security Tracker / security-tracker Commits: 551af19f by Arturo Borrero Gonzalez at 2024-09-23T22:13:20+02:00 CVE-2024-6609: bullseye: mark as fixed in nss > 3.61 The upstream source code for nss starting with 3.61 contains the

[Git][security-tracker-team/security-tracker][master] CVE-2023-6135: mark as ignored for debian bullseye

2024-09-23 Thread @arturo
Arturo Borrero González pushed to branch master at Debian Security Tracker / security-tracker Commits: 88b4b247 by Arturo Borrero Gonzalez at 2024-09-23T21:49:22+02:00 CVE-2023-6135: mark as ignored for debian bullseye Upstream says it is too invasive to fix. See also: https

[dev-tech-crypto] Re: running nss tests/all.sh for Debian package

2024-09-23 Thread Arturo Borrero Gonzalez
El viernes, 13 de septiembre de 2024 a las 19:13:37 UTC+2, Arturo Borrero Gonzalez escribió: Hi there, I'm working on improving CI integration for the nss debian package. [...] If I'm reading the script correctly, it mostly expects to be executed in the context of a freshly-built

[jira] [Commented] (HTTPCLIENT-2159) Invalid handling of charset content type parameter

2024-09-22 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2159?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17883624#comment-17883624 ] Arturo Bernal commented on HTTPCLIENT-2159: --- Hi [~michael-o]  [~res

Re: [VOTE][LAZY] Release HttpComponents CheckStyle 3 based on RC1

2024-09-22 Thread Arturo Bernal
+1 Arturo On Fri, Sep 20, 2024 at 3:46 PM Oleg Kalnichevski wrote: > Please lazy vote on releasing HttpComponents CheckStyle 3 based on RC1. > > The vote is open for the at least 72 hours, and only votes from > HttpComponents PMC members are binding. The vote passes if at least o

[jira] [Commented] (HTTPCLIENT-2343) Regression in setting USER_TOKEN context attribute in PoolingHttpClientConnectionManager

2024-09-21 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2343?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17883475#comment-17883475 ] Arturo Bernal commented on HTTPCLIENT-2343: --- HI [~bratkartoffel] 

[jira] [Commented] (HTTPCLIENT-2342) Regression: Content-Type header not returned anymore

2024-09-20 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2342?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17883231#comment-17883231 ] Arturo Bernal commented on HTTPCLIENT-2342: --- Hi [~ctabin]  I ran a

[jira] [Commented] (HTTPCLIENT-1843) Create module httpclient5-compress to use Apache Commons Compress

2024-09-19 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-1843?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17883111#comment-17883111 ] Arturo Bernal commented on HTTPCLIENT-1843: --- Hi [~ggregory] 

Re: [VOTE] Release HttpClient 5.4 based on RC1

2024-09-16 Thread Arturo Bernal
+1 Release the packages as HttpClient 5.4. Arturo On Mon, Sep 16, 2024 at 5:40 PM Oleg Kalnichevski wrote: > Please vote on releasing these packages as HttpClient 5.4. > The vote is open for the at least 72 hours, and only votes from > HttpComponents PMC members are binding. The vo

[dev-tech-crypto] running nss tests/all.sh for Debian package

2024-09-13 Thread Arturo Borrero Gonzalez
Hi there, I'm working on improving CI integration for the nss debian package. The nss testsuite (which can be run via tests/all.sh) contains a lot of test cases, and I would like to run this script from the debian CI infrastructure. Because the nss package in Debian can receive backported patc

[Git][security-tracker-team/security-tracker][master] LTS: claim nss in dla-needed.txt

2024-09-04 Thread @arturo
Arturo Borrero González pushed to branch master at Debian Security Tracker / security-tracker Commits: c0316a58 by Arturo Borrero Gonzalez at 2024-09-04T17:44:53+02:00 LTS: claim nss in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes

Debian LTS & ELTS report -- August 2024

2024-08-28 Thread Arturo Borrero Gonzalez
Hello, This is my August 2024 monthly report for the Freexian LTS/ELTS [1] initiative. Many thanks to Freexian and sponsors [2] for providing this opportunity! LTS: I did not engage in any LTS activities this month. ELTS: I spent my available time this month working on two packages:

Bug#1079219: RFP: LightPad -- A plugin for XFCE DE that shows a grid menu applications like GNOME

2024-08-21 Thread Arturo Ingenito
Package: wnpp Severity: wishlist Owner: Arturo Ingenito * Package name : lightpad Version : 0.0.8 Upstream Author : DEB Libre * URL : https://github.com/libredeb * License : GPL Description : A plugin for XFCE DE that shows a grid menu like GNOME The Lightpad plugin for XFCE is a lightweight

Bug#1079219: RFP: LightPad -- A plugin for XFCE DE that shows a grid menu applications like GNOME

2024-08-21 Thread Arturo Ingenito
Package: wnpp Severity: wishlist Owner: Arturo Ingenito * Package name : lightpad Version : 0.0.8 Upstream Author : DEB Libre * URL : https://github.com/libredeb * License : GPL Description : A plugin for XFCE DE that shows a grid menu like GNOME The Lightpad plugin for XFCE is a lightweight

Debian LTS & ELTS -- June 2024

2024-08-01 Thread Arturo Borrero Gonzalez
Hello, Here is my July 2024 monthly report for the Freexian LTS/ELTS [1] initiative. Many thanks to Freexian and sponsors [2] for providing this opportunity! This month, again, I would like to thank Santiago for the assistance, review and support. LTS: I did not engage in any LTS activi

Bug#1076389: ITS: rpmlint

2024-07-15 Thread Arturo Borrero Gonzalez
Please go ahead, no need for delay. I have no time (or interest) in this package anymore. You may drop me from the maintainer list as well.

[Cloud-announce] Toolforge operation scheduled for 2024-07-16 @ 09:00 UTC

2024-07-12 Thread Arturo Borrero Gonzalez
Hi there, The Toolforge Kubernetes system has been scheduled to be upgraded to version 1.25 [0] next Tuesday 2024-07-17 @ 09:00 UTC. The operation window will last 2 hours, and during this time, some Toolforge components will briefly and intermittently become unavailable. Examples of things

[Cloud] Toolforge operation scheduled for 2024-07-16 @ 09:00 UTC

2024-07-12 Thread Arturo Borrero Gonzalez
Hi there, The Toolforge Kubernetes system has been scheduled to be upgraded to version 1.25 [0] next Tuesday 2024-07-17 @ 09:00 UTC. The operation window will last 2 hours, and during this time, some Toolforge components will briefly and intermittently become unavailable. Examples of things

Re: Leer puerto desde RPGLE de una bascula

2024-07-10 Thread Jorge Arturo Perez
rights in the terms established in the > current regulations by contacting us. Likewise, you can request us to send > additional information about our data protection policy, tel 961 920 029, > e-mail: proteccionda...@silomar.es > > Únete a Recursos AS400, nuestra Comunidad ( http://bit.ly/db68dd ) > Forum.Help400 � Publicaciones Help400, S.L. > -- *Jorge Arturo Pèrez Osorio.* . Únete a Recursos AS400, nuestra Comunidad ( http://bit.ly/db68dd ) Forum.Help400 � Publicaciones Help400, S.L.

[GROW]Re: Working Group Call for Adoption for draft-ramseyer-grow-peering-api (start 07/Jun/2024 end 21/Jun/2024)

2024-07-02 Thread Arturo Servin
upport and something is missing, we are open to it. Regards as On Fri, 28 Jun 2024 at 19:06, Matthias Wichtlhuber < matthias.wichtlhu...@de-cix.net> wrote: > Hi Arturo, > > > One assumption that we have is that the Peering Database (in this case > PeeringDB but it could be any)

Debian LTS & ELTS -- June 2024

2024-06-30 Thread Arturo Borrero Gonzalez
Hello, Here is my June 2024 monthly report for the Freexian LTS/ELTS [1] initiative. Many thanks to Freexian and sponsors [2] for providing this opportunity! Turns out, this was my first month working on the LTS/ELTS projects, and I would like to thank Santiago for the assistance, review, suppo

Debian LTS & ELTS -- June 2024

2024-06-30 Thread Arturo Borrero Gonzalez
Hello, Here is my June 2024 monthly report for the Freexian LTS/ELTS [1] initiative. Many thanks to Freexian and sponsors [2] for providing this opportunity! Turns out, this was my first month working on the LTS/ELTS projects, and I would like to thank Santiago for the assistance, review, suppo

[SECURITY] [DLA 3846-1] libmojolicious-perl security update

2024-06-30 Thread Arturo Borrero Gonzalez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3846-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Arturo Borrero Gonzalez June 28, 2024

[Git][security-tracker-team/security-tracker][master] data/CVE/list: ignore nss CVE-2023-6135 in buster

2024-06-28 Thread @arturo
Arturo Borrero González pushed to branch master at Debian Security Tracker / security-tracker Commits: dd290270 by Arturo Borrero Gonzalez at 2024-06-28T23:28:37+02:00 data/CVE/list: ignore nss CVE-2023-6135 in buster Not fixing nss CVE-2023-6135 in Debian Buster. Signed-off-by: Arturo

Re: Bad signature for jspwiki-wikipages-de-2.12.2.zip

2024-06-28 Thread Arturo Bernal
Cheking Arturo On Fri, Jun 28, 2024 at 6:47 PM Florian Preinstorfer < lists-jspw...@nblock.org> wrote: > Hi, > Am 2024-06-26 19:09, schrieb Arturo Bernal: > >I apologize for the confusion and any inconvenience caused by the > >invalid signatures. If you encounter any fu

[GROW]Re: Working Group Call for Adoption for draft-ramseyer-grow-peering-api (start 07/Jun/2024 end 21/Jun/2024)

2024-06-28 Thread Arturo Servin
Matthias One assumption that we have is that the Peering Database (in this case PeeringDB but it could be any) is the canonical source of most of the information that you need to set up a peering session. In the case of RS, all that information is already there and there is no need to add it agai

Re: [VOTE] Release HttpCore 5.2.5 based on RC1

2024-06-27 Thread Arturo Bernal
+1 Release the packages as HttpCore 5.2.5. Arturo On Thu, Jun 27, 2024 at 10:25 AM Oleg Kalnichevski wrote: > Please vote on releasing these packages as HttpCore 5.2.5. > The vote is open for the at least 72 hours, and only votes from > HttpComponents PMC members are binding. The vo

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3846-1 for libmojolicious-perl

2024-06-27 Thread @arturo
Arturo Borrero González pushed to branch master at Debian Security Tracker / security-tracker Commits: 7c515ba9 by Arturo Borrero Gonzalez at 2024-06-27T22:59:02+02:00 Reserve DLA-3846-1 for libmojolicious-perl - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes

Re: [dev-tech-crypto] about CVE-2023-6125 in nss 3.42.1 in Debian Buster

2024-06-27 Thread Arturo Borrero Gonzalez
On 6/27/24 21:12, John Schanck wrote: Hi Arturo, we don't plan on backporting any of the patches for CVE-2023-6135 to the NSS 3.90 branch at this time. The patches you linked to are, unfortunately, not sufficient to fix the issue. Short of copying the entire lib/freebl/ecl directory fro

[jira] [Created] (JSPWIKI-1194) CI/CD Pipeline Optimization for Apache JSPWiki with JDK-17 Integration

2024-06-26 Thread Arturo Bernal (Jira)
Arturo Bernal created JSPWIKI-1194: -- Summary: CI/CD Pipeline Optimization for Apache JSPWiki with JDK-17 Integration Key: JSPWIKI-1194 URL: https://issues.apache.org/jira/browse/JSPWIKI-1194 Project

[jira] [Updated] (JSPWIKI-1194) CI/CD Pipeline Optimization for Apache JSPWiki with JDK-17 Integration

2024-06-26 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/JSPWIKI-1194?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Arturo Bernal updated JSPWIKI-1194: --- Assignee: Arturo Bernal > CI/CD Pipeline Optimization for Apache JSPWiki with JDK

Re: Bad signature for jspwiki-wikipages-de-2.12.2.zip

2024-06-26 Thread Arturo Bernal
reach out. Best regards, Arturo On Tue, Jun 25, 2024 at 11:38 AM Arturo Bernal wrote: > Hi All, > > I'm okay with not doing a new release and instead replacing the files that > have signature issues. > > > Arturo > > > On Mon, Jun 24, 2024 at

[Cloud-announce] Toolforge: introducing new security policy engine 2024-06-26 @ 08:30 UTZ

2024-06-25 Thread Arturo Borrero Gonzalez
Hi there, tomorrow 2024-06-26 @ 08:30Z we will start enforcing new Kubernetes security rules in Toolforge [0]. We have taken measures to eliminate any user impact, but this being a potentially sensitive change, I wanted to send a heads up email. In a nut-shell, pod-related kubernetes resour

Re: [dev-tech-crypto] about CVE-2023-6125 in nss 3.42.1 in Debian Buster

2024-06-25 Thread Arturo Borrero Gonzalez
On 6/24/24 18:25, Dana Keeler wrote: To save others from potential confusion, the CVE in question is CVE-2023-6135, not 6125. Correct, there was a typo on my side. -- You received this message because you are subscribed to the Google Groups "dev-tech-crypto@mozilla.org" group. To unsubscrib

Re: Bad signature for jspwiki-wikipages-de-2.12.2.zip

2024-06-25 Thread Arturo Bernal
Hi All, I'm okay with not doing a new release and instead replacing the files that have signature issues. Arturo On Mon, Jun 24, 2024 at 9:57 PM Juan Pablo Santos Rodríguez < juanpablo.san...@gmail.com> wrote: > Hi! > > my bad: gpg --keyserver hkps://pgp.mit.edu/ --re

Re: Bad signature for jspwiki-wikipages-de-2.12.2.zip

2024-06-24 Thread Arturo Bernal
Hi, The key is available (gpg --list-keys --fingerprint 2D51AAC6), but I don't think that will solve the issue. It seems that I might have generated the signature incorrectly. I checked and, yes, there are binaries that were signed correctly. Verification worked for jspwiki-portable-2.12.2-woas

Re: Bad signature for jspwiki-wikipages-de-2.12.2.zip

2024-06-24 Thread Arturo Bernal
resses all potential issues. what do you think? Best regards, Arturo On Sat, Jun 22, 2024 at 6:05 PM Arturo Bernal wrote: > Hi, > > Let me check. > > Cheers > > > Arturo > > > On Sat, Jun 22, 2024 at 6:03 PM Florian Preinstorfer < > lists-jspw...@nblock.o

Re: [VOTE] Release HttpClient 5.4-beta1 based on RC1

2024-06-24 Thread Arturo Bernal
+1 Release the packages as HttpClient 5.4-beta1. Arturo On Sun, Jun 23, 2024 at 11:09 AM Oleg Kalnichevski wrote: > Please vote on releasing these packages as HttpClient 5.4-beta1. > The vote is open for the at least 72 hours, and only votes from > HttpComponents PMC members are bin

[dev-tech-crypto] about CVE-2023-6125 in nss 3.42.1 in Debian Buster

2024-06-23 Thread Arturo Borrero Gonzalez
Hi there, I am exploring how to fix CVE-2023-6125 in the nss package (version 3.42.1) in Debian Buster. There is a note from a Debian college saying that we should wait until you have backported the fix to the 3.90 series, but scanning your releases did not immediately showed to me where (if

Re: Bad signature for jspwiki-wikipages-de-2.12.2.zip

2024-06-22 Thread Arturo Bernal
Hi, Let me check. Cheers Arturo On Sat, Jun 22, 2024 at 6:03 PM Florian Preinstorfer < lists-jspw...@nblock.org> wrote: > Hi, > it seems the GPG signature for jspwiki-wikipages-de-2.12.2.zip is > invalid: > >wget -q > https://archive.apache.org/dist/jspwiki/

[Git][security-tracker-team/security-tracker][master] data/dla-needed: claim libmojolicious-perl

2024-06-22 Thread @arturo
Arturo Borrero González pushed to branch master at Debian Security Tracker / security-tracker Commits: 7cf13c7e by Arturo Borrero Gonzalez at 2024-06-22T14:49:55+02:00 data/dla-needed: claim libmojolicious-perl Claim this package, I'll work on it. Signed-off-by: Arturo Borrero Gonzalez

[Git][security-tracker-team/security-tracker][master] data/dla-needed: add note about CVE-2023-6125 for nss

2024-06-22 Thread @arturo
Arturo Borrero González pushed to branch master at Debian Security Tracker / security-tracker Commits: e5209be0 by Arturo Borrero Gonzalez at 2024-06-22T14:08:07+02:00 data/dla-needed: add note about CVE-2023-6125 for nss Add new note. Signed-off-by: Arturo Borrero Gonzalez <

[jira] [Resolved] (HTTPCLIENT-2331) Single cookie header should be sent for multiple cookies

2024-06-19 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2331?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Arturo Bernal resolved HTTPCLIENT-2331. --- Resolution: Fixed Solved https://github.com/apache/httpcomponents-client/pull

[ANNOUNCE] Apache JSPWiki 2.12.2 released

2024-06-19 Thread Arturo Bernal
: https://jspwiki-wiki.apache.org/Wiki.jsp?page=NewIn2.12 We welcome your help and feedback. For more information on how to report problems, and to get involved visit the project website at http://jspwiki.apache.org/ The Apache JSPWiki Team Arturo

[ANNOUNCE] Apache JSPWiki 2.12.2 released

2024-06-19 Thread Arturo Bernal
: https://jspwiki-wiki.apache.org/Wiki.jsp?page=NewIn2.12 We welcome your help and feedback. For more information on how to report problems, and to get involved visit the project website at http://jspwiki.apache.org/ The Apache JSPWiki Team Arturo

Re: [VOTE] Release HttpCore 5.3-beta1 based on RC2

2024-06-18 Thread Arturo Bernal
+1 Release the packages as HttpCore 5.3-beta1. hashes match && signature verified Arturo On Mon, Jun 17, 2024 at 6:24 PM Oleg Kalnichevski wrote: > Please vote on releasing these packages as HttpCore 5.3-beta1. > The vote is open for the at least 72 hours, and o

Re: [VOTE] Release JSPWiki version 2.12.2

2024-06-17 Thread Arturo Bernal
Hi, +72 hours passed, we have 3 +1 votes - Murray Altheim - Juan Pablo Santos* - Harry Metske* - Arturo Bernal* 3 approved [+1] 1 don't mind [0] (* denoting PMC binding vote) so the vote passes :-) I'll proceed with the release Thanks to everyone that voted! cheers, Arturo O

Re: Issues Jenkins - release

2024-06-15 Thread Arturo Bernal
Hi Juan Pablo, Thanks for the detailed explanation. It makes sense. Let's fix it post-release. I´ll take a look after Cheers, Arturo On Fri, Jun 14, 2024 at 10:54 PM Juan Pablo Santos Rodríguez < juanpablo.san...@gmail.com> wrote: > Hi! > > I think everything is ok

Re: [VOTE] Release HttpCore 5.3-beta1 based on RC1

2024-06-15 Thread Arturo Bernal
+1 Release the packages as HttpCore 5.3-beta1. hashes match && signature verified Arturo On Fri, Jun 14, 2024 at 8:09 PM Oleg Kalnichevski wrote: > [VOTE] Release HttpCore 5.3-beta1 based on RC1 > > Please vote on releasing these packages as HttpCore 5.3-beta1. > The vot

Re: [VOTE] Release JSPWiki version 2.12.2

2024-06-15 Thread Arturo Bernal
Hi All, my +1 to the release. It makes sense to include the markdown files, and I have added them. Cheers, Arturo On Fri, Jun 14, 2024 at 10:57 PM Juan Pablo Santos Rodríguez < juanpablo.san...@gmail.com> wrote: > Hi! > > +1 > > just one minor nitpick, regarding t

Issues Jenkins - release

2024-06-14 Thread Arturo Bernal
rsion 2.12.13-snapshot when the code has version 2.12.2-snapshot. Any idea? Should I cancel and start over with another version RC2?? Thanks. Arturo

[VOTE] Release JSPWiki version 2.12.2

2024-06-12 Thread Arturo Bernal
/KEYS *** Please download, test and vote: [ ] +1 Approve the release [ ] 0 Don't mind [ ] -1 Disapprove the release (please provide specific comments) Arturo

Re: [connect-wg] BCOP for the use of IRR DBs in IXP RS - Last call

2024-06-12 Thread Arturo Servin via connect-wg
Hi I think that a big problem with this document is that it is trying to be BCOP without any practical operational deployment at all. So far, it is a theoretical document that we are not sure is going to work (for the reasons that we have pointed out.) >More broadly this approach would discourag

[Git][security-tracker-team/security-tracker][master] data/dla-needed: claim nss

2024-06-08 Thread @arturo
Arturo Borrero González pushed to branch master at Debian Security Tracker / security-tracker Commits: cbc31974 by Arturo Borrero Gonzalez at 2024-06-08T10:26:38+02:00 data/dla-needed: claim nss Claim the nss package. Signed-off-by: Arturo Borrero Gonzalez <art...@debian.org> - - - -

Re: [connect-wg] BCOP for the use of IRR DBs in IXP RS - Last call

2024-06-07 Thread Arturo Servin via connect-wg
On Thu, Jun 6, 2024 at 11:21 PM Barry O'Donovan (Open Solutions) < ba...@opensolutions.ie> wrote: > Hi all, > > > > One comment I did make was that it was paradoxical, on one hand, to > bemoan the depeering of large network(s) from route servers and discuss > how IXPs could engage to bring them ba

Re: [connect-wg] BCOP for the use of IRR DBs in IXP RS - Last call

2024-06-06 Thread Arturo Servin via connect-wg
Hi >But we are trying to solve only one aspect of the problem: by not using >anymore the unauthenticated IRRs we will have removed a whole class of >possibile hijackings. And also you might invalidate a lot of valid objects causing issues for the networks using the RS in the IX. Let me make a fe

Re: [hackers] [dmenu][patch] config.mk freebsd support

2024-06-04 Thread Roberto Arturo Gonzalez Godinez
Hola! Thank you for considering this small patch and for your fast reply! > though ${PREFIX}/lib and ${PREFIX}/include > actually depends on user-provided path (PREFIX), > I'm not sure that's what you actually want. That's correct, my mistake. I should of just written /usr/local/ instead. > A

[hackers] [dmenu][patch] config.mk freebsd support

2024-06-03 Thread Roberto Arturo Gonzalez Godinez
programs are in the FreeBSD ports, so someone must have already done this without submitting it to upstream? Hence the question if this is relevant. Thank you!From 71b156b5be45d8faf3ba670f20fa6840cd5dbdf8 Mon Sep 17 00:00:00 2001 From: Roberto Arturo Gonzalez Godinez Date: Tue, 4 Jun 2024 00:20:5

Re: 2.12.2 release?

2024-05-29 Thread Arturo Bernal
Hi, Ok to the release of version 2.12.2. I volunteer to act as the release manager. Arturo On Tue, May 28, 2024 at 9:52 PM Juan Pablo Santos Rodríguez < juanpablo.san...@gmail.com> wrote: > Hi! > > this weekend I pushed some commits to master regarding JSPWIKI-1186 > and

[SECURITY] [DLA 3820-1] bluez security update

2024-05-25 Thread Arturo Borrero Gonzalez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3820-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Arturo Borrero Gonzalez May 25, 2024

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3820-1 for bluez

2024-05-25 Thread @arturo
Arturo Borrero González pushed to branch master at Debian Security Tracker / security-tracker Commits: d96adff2 by Arturo Borrero Gonzalez at 2024-05-25T17:36:17+02:00 Reserve DLA-3820-1 for bluez - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] claim bluez in dla-needed.txt

2024-05-21 Thread @arturo
Arturo Borrero González pushed to branch master at Debian Security Tracker / security-tracker Commits: e9f0d7ac by Arturo Borrero Gonzalez at 2024-05-21T21:51:03+02:00 claim bluez in dla-needed.txt Claim the bluez package, and add a note. Signed-off-by: Arturo Borrero Gonzalez <

[Gretl-users] Re: Graph output

2024-05-20 Thread Cristián Arturo Ducoing Ruiz
[image: Graph.png] Danke Artur! El lun, 20 may 2024 a las 22:28, Artur T. () escribió: > Am 20.05.24 um 22:23 schrieb Cristián Arturo Ducoing Ruiz: > > Thanks Artur, > > > > My code below, example, to have the layout three graph in a the same row > > and in png fo

[Gretl-users] Re: Graph output

2024-05-20 Thread Cristián Arturo Ducoing Ruiz
ight of a gridplot. See here: > > https://gretl.sourceforge.net/gretl-help/cmdref.html#gridplot > > > Does it help? > > Best > Artur > > Am 20.05.24 um 22:04 schrieb Cristián Arturo Ducoing Ruiz: > > Hi there, > > > > I did some graphs with

[Gretl-users] Graph output

2024-05-20 Thread Cristián Arturo Ducoing Ruiz
the output is customizable, but I needed it in png. Any tips? I'm using the latest gretl version and windows 11 -- Atte. Cristián Arturo Ducoing Ruiz ___ Gretl-users mailing list -- gretl-users@gretlml.univpm.it To unsubscribe send an email to

Re: [Fail2ban-users] Fail2ban V1.1.0 from Github - question Regex

2024-05-20 Thread Arturo 'Buanzo' Busleiman
A tu servicio amigo. Enjoy fail2ban. You will succeed in learning it and stopping evil;) On Mon, May 20, 2024, 12:00 Maurizio Caloro wrote: > > > Am 20.05.2024 um 16:42 schrieb Arturo 'Buanzo' Busleiman < > bua...@buanzo.com.ar>: > >  > fail2ban-regex i

Re: [Fail2ban-users] Fail2ban V1.1.0 from Github - question Regex

2024-05-20 Thread Arturo 'Buanzo' Busleiman
fail2ban-regex is what you need to use... trust me on this, I have a bit of experience with fail2ban. XD On Mon, May 20, 2024, 11:41 Maurizio Caloro wrote: > > > Am 20.05.2024 um 16:30 schrieb Arturo 'Buanzo' Busleiman < > bua...@buanzo.com.ar>: > >  &g

Re: [Fail2ban-users] Fail2ban V1.1.0 from Github - question Regex

2024-05-20 Thread Arturo 'Buanzo' Busleiman
Howitt via Fail2ban-users < > fail2ban-users@lists.sourceforge.net>: > >  You also need to give us a bit more help, like examples of the failed > log you are trying to match. > > BTW, why try to match a port with \w+ and not \d+? And why \w+?. > > On 20/05/2024 13:36

Re: [Fail2ban-users] Fail2ban V1.1.0 from Github - question Regex

2024-05-20 Thread Arturo 'Buanzo' Busleiman
; > > > Please, after generate this syntax, no chance to include this to Fail2ban. > > From 4389 found 0 hits > > > > [Appl PyRex] > > NON-SMTP COMMAND from.\[+.\]:..after > CONNECT:.GET./.HTTP/1.1 > > NON-SMTP COMMAND from [64.62.197.214]:1

Re: [Fail2ban-users] Fail2ban V1.1.0 from Github - question Regex

2024-05-20 Thread Arturo 'Buanzo' Busleiman
Use pyrex or any python compatible one. Also be mindful of interpreting the filter definitions in filter.d and using fail2ban-regex as testing ground. On Mon, May 20, 2024, 07:21 Maurizio Caloro via Fail2ban-users < fail2ban-users@lists.sourceforge.net> wrote: > Hello > > Please i think the Ver

Re: HttpCore 5.3 / HttpClient 5.4 GA soon?

2024-05-16 Thread Arturo Bernal
Hi I agree, there seems to be no reason to delay. Let's proceed with the GA release of HttpCore 5.3 and HttpClient 5.4. +1 Arturo On Thu, May 16, 2024 at 3:44 PM Oleg Kalnichevski wrote: > Folks > > I do not think there is any good reason to delay the GA release of

[Gretl-users] Re: Possible bug in yahoo.get (spanish)

2024-05-14 Thread Cristián Arturo Ducoing Ruiz
ed ok Se ha generado la serie msft (ID 2) El mar, 14 may 2024 a las 8:52, Riccardo (Jack) Lucchetti (< p002...@staff.univpm.it>) escribió: > On 14/05/2024 08:33, Riccardo (Jack) Lucchetti wrote: > > On 14/05/2024 08:20, Cristián Arturo Ducoing Ruiz wrote: > >> Thanks for

[Gretl-users] Re: Possible bug in yahoo.get (spanish)

2024-05-13 Thread Cristián Arturo Ducoing Ruiz
English, "MSFT imported ok" I will try it again with other languages and I come back to you Best El mar, 14 may 2024 a las 8:06, Riccardo (Jack) Lucchetti (< p002...@staff.univpm.it>) escribió: > On 14/05/2024 07:44, Artur T. wrote: > > Am 14.05.24 um 01:06 schrieb Cri

[Gretl-users] Possible bug in yahoo.get (spanish)

2024-05-13 Thread Cristián Arturo Ducoing Ruiz
using the same code, I got immediately the data requested (MSFT) include yahoo_get.gfn series msft = yahoo_price("MSFT", 1) MSFT imported ok Generated series msft (ID 2) Im using windows 11 and the latest gretl version (2024a) Best regards -- Atte. Cristián

Re: 2.12.2 release?

2024-05-13 Thread Arturo Bernal
need to address the commit related to the virtual threat, but I'll prioritize the release and the security fixes. Best regards, Arturo On Thu, May 9, 2024 at 11:30 PM Juan Pablo Santos Rodríguez < juanpablo.san...@gmail.com> wrote: > Hi, > > we've been some months with

[plasmashell] [Bug 341143] Bring back per-virtual-desktop wallpapers

2024-04-21 Thread Octavio Arturo Guerrero Rivera
https://bugs.kde.org/show_bug.cgi?id=341143 Octavio Arturo Guerrero Rivera changed: What|Removed |Added CC||octa...@null.net -- You are

[dolphin] [Bug 169405] Save icon size per-directory

2024-04-21 Thread Octavio Arturo Guerrero Rivera
https://bugs.kde.org/show_bug.cgi?id=169405 Octavio Arturo Guerrero Rivera changed: What|Removed |Added CC||octa...@null.net -- You are

[frameworks-kwindowsystem] [Bug 335161] get_stringlist_reply returns invalid data for single item lists

2024-04-21 Thread Octavio Arturo Guerrero Rivera
https://bugs.kde.org/show_bug.cgi?id=335161 Octavio Arturo Guerrero Rivera changed: What|Removed |Added CC||octa...@null.net -- You are

Bug#1069289: arguments to dbus_server_get_address() were incorrect, assertion "server != NULL" failed in file ../../../dbus/dbus-server.c line 840

2024-04-19 Thread Arturo Borrero Gonzalez
Source: sssd Version: 2.8.2-4 Severity: normal Tags: upstream Hi there, thanks for your work with the sssd packages, really appreciated. Today I found this assert that is preventing the sssd.service from starting: Apr 19 14:02:17 debian sssd[586]: Starting up Apr 19 14:02:17 debian sssd[586]: d

  1   2   3   4   5   6   7   8   9   10   >