Bug#1088649: imagick autopkgtest

2024-11-29 Thread Bastien Roucariès
control: tags -1 + patch Hi, You forget to upgrade the test dependency to newer imagemagick and imagemagick library Bastien signature.asc Description: This is a digitally signed message part.

Bug#1086224: RC: Argument " " isn't numeric in division (/) at /usr/share/perl5/GD/SecurityImage/Magick.pm

2024-11-05 Thread Bastien Roucariès
control: tags -1 + important Le mardi 29 octobre 2024, 17:18:03 UTC gregor herrmann a écrit : > On Tue, 29 Oct 2024 16:08:30 +, Niko Tyni wrote: > > > This gives a list of thirteen integers on trixie, but > > just one undef on sid. > > > > Is this an intentional API change in ImageMagick 7 t

Bug#1086224: RC: Argument " " isn't numeric in division (/) at /usr/share/perl5/GD/SecurityImage/Magick.pm

2024-10-29 Thread Bastien Roucariès
Le mardi 29 octobre 2024, 16:08:30 UTC Niko Tyni a écrit : > On Tue, Oct 29, 2024 at 07:59:25AM +0000, Bastien Roucariès wrote: > > Package: libgd-securityimage-perl > > Version: 1.75-3 > > Severity: serious > > Justification: Break transition imagemagick 7 > > &

Bug#1086224: RC: Argument " " isn't numeric in division (/) at /usr/share/perl5/GD/SecurityImage/Magick.pm

2024-10-29 Thread Bastien Roucariès
Package: libgd-securityimage-perl Version: 1.75-3 Severity: serious Justification: Break transition imagemagick 7 Dear Maintainer, Last autopkgtest for imagemagick7 fail with a lot of message on stderr. I suppose a depends on fonts is missing: 30s Argument " " isn't numeric in division (/) at /

Bug#1085455: form-history-control: dompurify

2024-10-19 Thread Bastien Roucariès
Source: form-history-control Version: dompurify Severity: serious Tags: security Justification: security X-Debbugs-Cc: Debian Security Team Dear Maintainer, you include a copy a dompurify that seems to be affected by recent CVE https://sources.debian.org/src/form-history-control/2.5.1.0-1/commo

Bug#1085453: dompurify

2024-10-19 Thread Bastien Roucariès
Source: mediawiki Severity: serious Tags: upstream security Dear Maintainer, Dompurify was affected recently by a few security bug Can you cross check that you patched the problem https://sources.debian.org/src/mediawiki/1:1.39.10-1/extensions/VisualEditor/lib/ve/lib/dompurify/ Better will be

Bug#1084993: docker.io: CVE-2024-41110

2024-10-12 Thread Bastien Roucariès
Source: docker.io Version: 20.10.24+dfsg1-1 Severity: serious Tags: security Justification: security Dear Maintainer, security vulnerability has been detected in certain versions of Docker Engine, which could allow an attacker to bypass authorization plugins (AuthZ) under specific circumstances.

Bug#1081316: marked as pending in lintian

2024-09-10 Thread Bastien Roucariès
Control: tag -1 pending Hello, Bug #1081316 in lintian reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/lintian/lintian/-/commit/df6b9c2582f5a409342b2f03d52069f8

Bug#1079335: synfig: FTBFS ffmpeg

2024-08-22 Thread Bastien Roucariès
Source: synfig Severity: serious Tags: ftbfs Justification: ftbfs Dear Maintainer, Your package fail to build from source, and seems to be related to ffmpeg Tested during rebuild for imagemagick could be found here https://salsa.debian.org/debian/imagemagick/-/jobs/6164328 configure:22159: resu

Bug#1079288: virtuoso-opensource: FTBFS

2024-08-22 Thread Bastien Roucariès
Source: virtuoso-opensource Severity: serious Tags: ftbfs sid Justification: FTBFS Dear Maintainer, Your package FTBFS: Dksesstr.c: In function 'strdev_free_buf': Dksesstr.c:152:44: warning: unused parameter 'arg' [-Wunused-parameter] 152 | strdev_free_buf (buffer_elt_t * b, caddr_t arg)

Bug#1078951: civicrm: include vulnerable sinon without source

2024-08-18 Thread Bastien Roucariès
Source: civicrm Severity: serious Tags: security Justification: security problem X-Debbugs-Cc: Debian Security Team Dear Maintainer, You include a sinon in installed package and bundle without source (thus serious bug). This a duplication of package but moreover a security problem (even if mino

Bug#1078705: lintian FTBFS: lintian-overrides/mystery/fields-multi-arch-same-package-has-arch-specific-overrides

2024-08-14 Thread Bastien Roucariès
Le mercredi 14 août 2024, 14:47:30 UTC Helmut Grohne a écrit : > Source: lintian > Version: 2.118.0 > Severity: serious > Tags: ftbfs > > I attempted building lintian in unstable and this is what I got. > > | > debian/test-out/eval/checks/debian/lintian-overrides/malformed/missing-colon/generic.

Bug#1076350: May be related

2024-08-02 Thread Bastien Roucariès
Hi Can this bug could be due to libuv According to https://lists.archlinux.org/pipermail/arch-ports/2018-November/000839.html thread Did you try to recompile without --shared-libuv ? Bastien signature.asc Description: This is a digitally signed message part.

Bug#1077557: marked as pending in lintian

2024-07-30 Thread Bastien Roucariès
Control: tag -1 pending Hello, Bug #1077557 in lintian reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/lintian/lintian/-/commit/8333bc744ffabcdca355d07efd0bd001

Bug#1077557: Most changelog items missing in 2.117.1 changelog entry (Re: lintian_2.117.1_source.changes ACCEPTED into unstable)

2024-07-29 Thread Bastien Roucariès
e > > Version: 2.117.1 > > Distribution: unstable > > Urgency: medium > > Maintainer: Debian Lintian Maintainers > > Changed-By: Bastien Roucariès > > Closes: 1077112 > > Changes: > > lintian (2.117.1) unstable; urgency=medium > >

Bug#1074391: More information

2024-06-29 Thread Bastien Roucariès
control: severity -1 important control: retitle -1 should be split between arch and arch:all Thanks to Yadd partially solved. However this package should be split between arch and arch:all part Bastien > On 6/28/24 01:04, Bastien Roucariès wrote: > > Hi, > > > > I get

Bug#1074391: More information

2024-06-27 Thread Bastien Roucariès
Hi, I get this backtrace (yadd could you get a glimpse) Error [ERR_MODULE_NOT_FOUND]: Cannot find package 'esbuild' imported from assemblyscript/assemblyscript/scripts/build.js Did you mean to import "file:///usr/lib/x86_64-linux-gnu/nodejs/esbuild/lib/main.js"? at packageResolve (node:inte

Bug#1074391: esbuild: build esbuild main.js

2024-06-27 Thread Bastien Roucariès
Package: esbuild Version: 0.20.2-1 Severity: serious Justification: could not be imported from node Dear Maintainer, Could you build the node package esbuild ? Without it the package is broken from node point of view so serious bug. I can help here Bastien signature.asc Description: This is

Bug#1073290: systemd: Please breaks against dracut-core << 102-2~

2024-06-16 Thread Bastien Roucariès
Package: systemd Severity: serious Tags: patch Justification: Breaks unrelated package Control: affects -1 dracut-core Dear Maintainer, Following #1071182 could you add to systemd a breaks: dracut-core << 102-2~ Change is simple so I add patch tag, please remove if needed Bastien signature.a

Bug#1070069: fossil: CVE-2024-24795 unreleated breakage

2024-05-06 Thread Bastien Roucariès
Le lundi 29 avril 2024, 18:40:39 UTC Barak A. Pearlmutter a écrit : > Bastien, > > Okay, got it. Thanks for letting me know. > > I can cherry-pick that fossil commit, but you know the right magic for > a versioned apache2 breakage and how to deal with proposed-updates. > So I think it would make

Bug#1070069: fossil: CVE-2024-24795 unreleated breakage

2024-04-30 Thread Bastien Roucariès
Le mardi 30 avril 2024, 14:56:07 UTC Barak A. Pearlmutter a écrit : > I've uploaded a package with this fixed to unstable, 1:2.24-5, and > it's been autobuilt and pushed out. Seems to work okay, and can be > co-installed with apache2/sid. > > Just uploaded 1:2.24-6 that adds Breaks: apach2-bin per

Bug#1070069: fossil: CVE-2024-24795 unreleated breakage

2024-04-30 Thread Bastien Roucariès
Le mardi 30 avril 2024, 14:56:07 UTC Barak A. Pearlmutter a écrit : > currently Debian sqlite3 is > compiled without SQLITE_ENABLE_JSON1 so the internal version is used.) On this proble could you cross check ? >SQLITE_ENABLE_JSON1 > >This compile-time option is a no-op. Prior to SQLite version

Bug#1070069: fossil: CVE-2024-24795 unreleated breakage

2024-04-30 Thread Bastien Roucariès
Le lundi 29 avril 2024, 18:40:39 UTC Barak A. Pearlmutter a écrit : > Bastien, > > Okay, got it. Thanks for letting me know. > > I can cherry-pick that fossil commit, but you know the right magic for > a versioned apache2 breakage and how to deal with proposed-updates. > So I think it would make

Bug#1070069: fossil: CVE-2024-24795 unreleated breakage

2024-04-29 Thread Bastien Roucariès
Le lundi 29 avril 2024, 18:40:39 UTC Barak A. Pearlmutter a écrit : > Bastien, > > Okay, got it. Thanks for letting me know. > > I can cherry-pick that fossil commit, but you know the right magic for > a versioned apache2 breakage and how to deal with proposed-updates. > So I think it would make

Bug#1070069: fossil: CVE-2024-24795 unreleated breakage

2024-04-29 Thread Bastien Roucariès
Package: fossil Severity: serious Justification: break unreleated package affects: apache2 Dear Maintainer, CVE-2024-24795 is fixed in apache2. However it break fossil You need to apply https://fossil-scm.org/home/info/f4ffefe708793b03 See bug here: https://bz.apache.org/bugzilla/show_bug.cgi?i

Bug#1061519: shim: CVE-2023-40546 CVE-2023-40547 CVE-2023-40548 CVE-2023-40549 CVE-2023-40550 CVE-2023-40551

2024-04-17 Thread Bastien Roucariès
Le lundi 15 avril 2024, 13:58:19 UTC Steve McIntyre a écrit : > On Mon, Apr 15, 2024 at 11:33:14AM +0000, Bastien Roucariès wrote: > >Source: shim > >Followup-For: Bug #1061519 > >Control: tags -1 + patch > > > >Dear Maintainer, > > > >Please find a

Bug#1061519: shim: CVE-2023-40546 CVE-2023-40547 CVE-2023-40548 CVE-2023-40549 CVE-2023-40550 CVE-2023-40551

2024-04-15 Thread Bastien Roucariès
Source: shim Followup-For: Bug #1061519 Control: tags -1 + patch Dear Maintainer, Please find a MR here https://salsa.debian.org/efi-team/shim/-/merge_requests/13 Bastien signature.asc Description: This is a digitally signed message part.

Bug#1064061: CVE-2023-52160

2024-04-12 Thread Bastien Roucariès
control: tags -1 + patch Hi, You will find a merge request for fixing CVE-2023-52160 https://salsa.debian.org/debian/wpa/-/merge_requests/15 I can do a NMU if neeeded Bastien signature.asc Description: This is a digitally signed message part.

Bug#1067017: jupyterlab: Use node-long package

2024-03-16 Thread Bastien Roucariès
Source: jupyterlab Version: 4.0.11+ds1-1 Severity: serious Justification: duplicate code source not build from source Dear Maintainer, Your package include the following file packaged elsewhere python3-jupyterlab: /usr/share/jupyter/lab/staging/node_modules/@xtuc/long/LICENSE python3-jupyterlab:

Bug#1061272: sudo: Does not build from prefered source

2024-01-21 Thread Bastien Roucariès
Source: sudo Severity: serious Tags: ftbfs Justification: yacc/lex are prefered source Dear Maintainer, You do not pass the --with-devel=yes configure flags thus you do not rebuild from source autogenerated file like gram.c and gram.h from gram.y Usually debian build from source grammar file par

Bug#1055328: node-minimatch: could not build using webpack

2023-11-04 Thread Bastien Roucariès
Package: node-minimatch Version: 9.0.3-4 Severity: serious Justification: FTBFS other package Dear Maintainer, I could not build node-envinfo due to the trick done for default export only for require. Webpack do a mix of two and do not find the import default... Therefore it is required to expor

Bug#1054444: golang-github-facebook-ent: website is build with Docusaurus not packaged for debian

2023-10-24 Thread Bastien Roucariès
control: retitle -1 golang-github-facebook-ent: include non free font Calibre Le mardi 24 octobre 2023, 06:13:41 UTC Cyril Brulebois a écrit : > Hi Bastien, > > Bastien Roucariès (2023-10-23): > > Source: golang-github-facebook-ent > > Version: 0.5.4-3 > > Severi

Bug#1054433: node-puppeteer: website is build with Docusaurus not packaged for debian

2023-10-24 Thread Bastien Roucariès
control: retitle -1 fasttext: website is build with Docusaurus not packaged for debian Le mardi 24 octobre 2023, 06:41:55 UTC Andrius Merkys a écrit : > Hi, > > On 2023-10-23 22:06, Bastien Roucariès wrote: > > Source: fasttext > > Source package names in Subject an

Bug#1054432: [Pkg-javascript-devel] Bug#1054432: node-puppeteer: website is build with Docusaurus not packaged for debian

2023-10-24 Thread Bastien Roucariès
control: retitle -1 node-katex: website is build with Docusaurus not packaged for debian Le mardi 24 octobre 2023, 06:40:59 UTC Andrius Merkys a écrit : > Hi, > > On 2023-10-23 22:04, Bastien Roucariès wrote: > > Source: node-katex > > Source package names in Subject an

Bug#1054444: golang-github-facebook-ent: website is build with Docusaurus not packaged for debian

2023-10-23 Thread Bastien Roucariès
Source: golang-github-facebook-ent Version: 0.5.4-3 Severity: serious Tags: ftbfs Justification: FTBFS Control: block -1 by 1054426 Dear Maintainer, The documentation is build with docusaurus. See website directory https://sources.debian.org/src/golang-github-facebook-ent/0.5.4-3/doc/website/

Bug#1054443: node-graphql: website is build with Docusaurus not packaged for debian

2023-10-23 Thread Bastien Roucariès
Source: node-graphql Version: 16.8.1-1 Severity: serious Tags: ftbfs Justification: FTBFS Control: block -1 by 1054426 Dear Maintainer, The documentation is build with docusaurus. See website directory https://sources.debian.org/src/node-graphql/16.8.1-1/website/src/pages/index.jsx/?hl=2#L2 Y

Bug#1054440: reassign

2023-10-23 Thread Bastien Roucariès
control: reassign -1 ts-node signature.asc Description: This is a digitally signed message part.

Bug#1054441: node-ts-jest: website is build with Docusaurus not packaged for debian

2023-10-23 Thread Bastien Roucariès
Source: node-ts-jest Version: 29.1.1+~cs0.2.6-2 Severity: serious Tags: ftbfs Justification: FTBFS Control: block -1 by 1054426 Dear Maintainer, The documentation is build with docusaurus. See website directory https://sources.debian.org/data/main/n/node-ts-jest/29.1.1%2B~cs0.2.6-2/website/ Yo

Bug#1054440: ts-node: website is build with Docusaurus not packaged for debian

2023-10-23 Thread Bastien Roucariès
Source: ts-nod Version: 10.9.1+~cs8.8.29-1 Severity: serious Tags: ftbfs Justification: FTBFS Control: block -1 by 1054426 Dear Maintainer, The documentation is build with docusaurus. See website directory https://sources.debian.org/src/ts-node/10.9.1%252B~cs8.8.29-1/website/ You should repac

Bug#1054439: node-rjsf: website is build with Docusaurus not packaged for debian

2023-10-23 Thread Bastien Roucariès
Source: node-rjsf Version: 5.6.2+~5.0.1-1 Severity: serious Tags: ftbfs Justification: FTBFS Control: block -1 by 1054426 Dear Maintainer, The documentation is build with docusaurus. See website directory https://sources.debian.org/src/node-rjsf/5.6.2+~5.0.1-1/packages/docs/docusaurus.config.js

Bug#1054438: golang-entgo-ent: website is build with Docusaurus not packaged for debian

2023-10-23 Thread Bastien Roucariès
Source: golang-entgo-ent Version: 0.11.3-4 Severity: serious Tags: ftbfs Justification: FTBFS Control: block -1 by 1054426 Dear Maintainer, The documentation is build with docusaurus. See website directory https://sources.debian.org/data/main/g/golang-entgo-ent/0.11.3-4/doc/website You should

Bug#1054437: golang-ariga-atlas: website is build with Docusaurus not packaged for debian

2023-10-23 Thread Bastien Roucariès
Source: golang-ariga-atlas Version: 0.7.2-2 Severity: serious Tags: ftbfs Justification: FTBFS Control: block -1 by 1054426 Dear Maintainer, The documentation is build with docusaurus. See website directory https://sources.debian.org/src/golang-ariga-atlas/0.7.2-2/doc/website/ You should repac

Bug#1054435: node-react-redux: website is build with Docusaurus not packaged for debian

2023-10-23 Thread Bastien Roucariès
Source: node-react-redux Version: 8.1.2+dfsg1+~cs1.2.3-1 Severity: serious Tags: ftbfs Justification: FTBFS Control: block -1 by 1054426 Dear Maintainer, The documentation is build with docusaurus. See website directory You should repack or package docusaurus and rebuild Bastien signature.a

Bug#1054434: node-redux: website is build with Docusaurus not packaged for debian

2023-10-23 Thread Bastien Roucariès
Source: node-redux Version: 4.2.1-1 Severity: serious Tags: ftbfs Justification: FTBFS Control: block -1 by 1054426 Dear Maintainer, The documentation is build with docusaurus. See website directory You should repack or package docusaurus and rebuild Bastien signature.asc Description: This

Bug#1054433: node-puppeteer: website is build with Docusaurus not packaged for debian

2023-10-23 Thread Bastien Roucariès
Source: fasttext Version: 0.9.2+ds-5 Severity: serious Tags: ftbfs Justification: FTBFS Control: block -1 by 1054426 Dear Maintainer, The documentation is build with docusaurus. See website directory You should repack or package docusaurus and rebuild Bastien signature.asc Description: This

Bug#1054432: node-puppeteer: website is build with Docusaurus not packaged for debian

2023-10-23 Thread Bastien Roucariès
Source: node-katex Version: 0.16.4+~cs6.1.0-1 Severity: serious Tags: ftbfs Justification: FTBFS Control: block -1 by 1054426 Dear Maintainer, The documentation is build with docusaurus. See: https://sources.debian.org/src/node-katex/0.16.4+~cs6.1.0-1/website/ You should repack or package docu

Bug#1054431: node-puppeteer: website is build with Docusaurus not packaged for debian

2023-10-23 Thread Bastien Roucariès
Source: node-puppeteer Version: 13.4.1+dfsg-2 Severity: serious Tags: ftbfs Justification: FTBFS Control: block -1 by 1054426 Dear Maintainer, The documentation is build with docusaurus. See: https://sources.debian.org/src/node-puppeteer/13.4.1+dfsg-2/website/ You should repack or package docus

Bug#1051089: Fwd: Moreinformation

2023-10-21 Thread Bastien Roucariès
control: tags -1 + moreinfo Hi, >ruby-rails-assets-punycode depends on libjs-punycode but nothing >builds that package. It used to be provided by the same source >package. I do not understand what break libjs-punycode is provided by node-punycode See https://tracker.debian.org/media/packages/n

Bug#1051474: libreoffice: Please add embeded code copies to embeded-code-copies on security tracker debian.tar.xz/tarballs

2023-09-08 Thread Bastien Roucariès
Source: libreoffice Severity: serious Tags: security Justification: Document embdeded code copy + copyright X-Debbugs-Cc: Debian Security Team Dear Maintainer, Could you document that you embded a few tar ball under the security tracker ? For oldstable/stable/unstable Version should be document

Bug#1042757: ublock-origin: embded javascript lib

2023-08-18 Thread Bastien Roucariès
Le vendredi 18 août 2023, 23:16:04 UTC Markus Koschany a écrit : > Am Montag, dem 31.07.2023 um 11:56 + schrieb Bastien Roucariès: > > Source: ublock-origin > > Severity: serious > > Justification: not prefered form of modification > > > > Dear Maintaine

Bug#1042970: zoneminder: Embded cakephp

2023-08-03 Thread Bastien Roucariès
Source: zoneminder Severity: serious Justification: embded code copy Dear Maintainer, Your package include a copy of cake php. Could you use the packaged one ? Thanks signature.asc Description: This is a digitally signed message part.

Bug#976697: webext-umatrix: no longer developed upstream, remove or switch to LibreMatrix or?

2023-07-31 Thread Bastien Roucariès
Source: umatrix Followup-For: Bug #976697 Forwarded: https://gitlab.com/vannilla/ematrix/ Dear Maintainer, I have asked guidance to the last fork about firefox/chromium support. If not RM is the wayto go Bastien -- System Information: Debian Release: trixie/sid APT prefers testing-debug AP

Bug#1042757: ublock-origin: embded javascript lib

2023-07-31 Thread Bastien Roucariès
Source: ublock-origin Severity: serious Justification: not prefered form of modification Dear Maintainer, src/lib include a few library that are already packaged for debian. per se it is not a serious bug, but we should try if possible after testing to use packaged version The serious bug is du

Bug#1042738: ruby-rails-assets-punycode: Do not ship libjs-punycode

2023-07-31 Thread Bastien Roucariès
Source: ruby-rails-assets-punycode Severity: serious Justification: source is missing Dear Maintainer, You package node-punycode without source... I plan to fix this Bastien signature.asc Description: This is a digitally signed message part.

Bug#1042715: php-horde-editor: Please drop ckeditor3

2023-07-30 Thread Bastien Roucariès
Source: php-horde-editor Severity: serious Tags: security Justification: security reason EOL X-Debbugs-Cc: Debian Security Team Dear Maintainer, ckeditor4 go to EOL since June by upstream. You use ckeditor3. With my javascript hat maint of ckeditor I think we could migrate your software to cked

Bug#1042533: netdata: Please use packaged pako

2023-07-29 Thread Bastien Roucariès
Source: netdata Severity: serious Dear Maintainer, pako is packaged for debian as node-pako and minify now under /usr/share/javascript/pako Moreover the first line of your missing source show a webpack line so your source are not on the prefered form and thus this is a serious bug You should al

Bug#1042532: mediawiki: Vendoring a few javascript library without source

2023-07-29 Thread Bastien Roucariès
Source: mediawiki Version: 1:1.39.4-2 Severity: serious Justification: missing source Dear Maintainer, resources/lib/ (https://sources.debian.org/src/mediawiki/1:1.39.4-2/resources/lib/) include a few library already packaged for debian. Moreover some source are missing (I have only checked pak

Bug#1042531: novnc: Embded copy of node-pako

2023-07-29 Thread Bastien Roucariès
Source: novnc Severity: serious Justification: embed code copy Dear Maintainer, Your package include an embded code copy of node-pako (under vendor) Could you please use the packaged node-pako ? Thanks bastien signature.asc Description: This is a digitally signed message part.

Bug#1042529: sogo: Multiple embdeded and minified javascript library

2023-07-29 Thread Bastien Roucariès
Source: sogo Severity: serious Tags: ftbfs security Justification: FTBFS + security X-Debbugs-Cc: Debian Security Team Dear Maintainer, https://sources.debian.org/src/sogo/5.8.4-1/UI/WebServerResources/js/vendor/ inlclude a few library precompiled and that seems outdated (bad from a security poi

Bug#1042528: ldap-account-manager: Multiple embeded and minified javascript library

2023-07-29 Thread Bastien Roucariès
Source: ldap-account-manager Severity: serious Tags: ftbfs security Justification: FTBFS + security Dear Maintainer, Ldap-account-manager include a few vendored and outdated (without security support) javascript library Could you remove this depends and use packaged library Thanks

Bug#1042527: request-tracker5: Include ckeditor minimified

2023-07-29 Thread Bastien Roucariès
Source: request-tracker5 Severity: serious Tags: ftbfs Justification: FTBFS Control: tags -1 + security Dear Maintainer, https://sources.debian.org/src/request- tracker5/5.0.3+dfsg-3/share/static/RichText/ include ckeditor outdated (with CVE) and moreover minified Could you use the packaged cke

Bug#1041471: Reassign

2023-07-27 Thread Bastien Roucariès
control: reopen -1 control: notfound -1 19 control: reassign -1 qemu-user control: found -1 1:8.0.2+dfsg-3 control: found -1 control: forwarded -1 https://gitlab.com/qemu-project/qemu/-/issues/1776 control: affects -1 src:isa-support control: severity -1 important Hi, THis is a qemu bug mark as

Bug#1040141: FTBFS: FAIL: TestCheckoutGit

2023-07-02 Thread Bastien Roucariès
Source: docker.io Version: 18.09.1+dfsg1-7.1+deb10u3 Severity: serious Justification: FTBFS X-Debbugs-Cc: debian-...@lists.debian.org Dear Maintainer, The current security version FTBFS for me with -- FAIL: TestCheckoutGit (0.52s) gitutils_test.go:188: assertion failed: error is not nil: exit

Bug#1039438: enigma: Embded and use lua copy (outdated)

2023-06-25 Thread Bastien Roucariès
Source: enigma Severity: serious Tags: security Justification: embded X-Debbugs-Cc: Debian Security Team Dear Maintainer, You ship a outdated and embed lua: - could you use the system library - repack in order to avoid compiling accidentally the embded version Bastien -- System Information: D

Bug#1039119: darktable: use packaged lua

2023-06-25 Thread Bastien Roucariès
Source: darktable Version: Use packaged lua Severity: serious Justification: embded code copy Dear Maintainer, It appear that your package embded and compile lua Could you: - use the packaged lua lib - repack in order to avoid accidental reintroduction of compiling lua rouca -- System Informa

Bug#1039088: whitedb: embed yajl

2023-06-25 Thread Bastien Roucariès
Source: whitedb Version: embed yajl Severity: serious Justification: devref Dear Maintainer, Your package embed a copy of yajl. Could you: - compile against debian yajl package - remove by repacking the yajl code copy in order to accidentally compile the embed code copy Thanks Rouca -- System

Bug#1039087: epic-base: embed yajl

2023-06-25 Thread Bastien Roucariès
Source: epic-base Severity: serious Justification: devref Dear Maintainer, Your package embed a copy of yajl. Could you: - compile against the packaged yajl package - remove by repacking the embded code copy in order to avoid accidental compilation of the embed code copy Thanks Rouca -- Syst

Bug#1039086: collada2gltf: Embed yajl

2023-06-25 Thread Bastien Roucariès
Source: collada2gltf Severity: serious Justification: devref Dear Maintainer, Your package embed a copy a yajl Could you: - build against yajl package - remove by repacking the code copy in order to avoid in the future accidental code compilation against the embed code copy Thanks Bastien --

Bug#1039085: burp: embed yajl

2023-06-25 Thread Bastien Roucariès
Source: burp Severity: serious Justification: devref Dear Maintainer, Your package embed a code copy of yajl. Could you: - build against yajl debian package - repack your package removing the emded code copy in order to avoid accidental compilation in future. Thanks rouca -- System Informatio

Bug#1039083: crun: Embed yajl

2023-06-25 Thread Bastien Roucariès
Source: crun Severity: serious Justification: embed code copy devref Dear Maintainer, Your package include an embed code copy of yajl Could you please: - deembed - the repack (+ds source if needed) in order to be sure it will be not compiled in by accident in newer release Thanks Bastien -- S

Bug#1038902: docker.io: FTBFS skip btrfs

2023-06-22 Thread Bastien Roucariès
Source: docker.io Severity: serious Tags: ftbfs control: tags -1 + patch Justification: FTBFS Dear Maintainer, I had applied the following patch for compiling under btrfs for buster. Could you refresh and apply for other version BastienFrom: =?utf-8?q?Bastien_Roucari=C3=A8s?= Date: Thu, 22 Jun

Bug#1033223: chromium: #ozone-platform-hint should be set to auto

2023-03-20 Thread Bastien Roucariès
Package: chromium Version: 111.0.5563.64-1 Severity: serious Tags: patch Justification: unusable under wayland kde Dear Maintainer, Under wayland chromium tab are unresponsible to mouse. #ozone-platform-hint set to auto instead of default help here to detect wayland. Could you set this option ?

Bug#1032188: old old stable debdiff

2023-03-01 Thread Bastien Roucariès
triggered +via the parse function. +Fix CVE-2022-21222, CVE-2021-33587 (Closes: #989264, #1032188) + + -- Bastien Roucariès Wed, 01 Mar 2023 15:33:15 + + node-css-what (2.1.0-1) unstable; urgency=medium * new upstream version diff -Nru node-css-what-2.1.0/debian/patches/0001-Partial

Bug#1032188: Old stable debdiff

2023-03-01 Thread Bastien Roucariès
expression in the +re_attr variable. +The exploitation of this vulnerability could be triggered +via the parse function. +Fix CVE-2022-21222, CVE-2021-33587 (Closes: #989264, #1032188) + + -- Bastien Roucariès Wed, 01 Mar 2023 15:33:15 + + node-css-what (2.1.0-1) unstable

Bug#1032188: debdiff

2023-03-01 Thread Bastien Roucariès
+re_attr variable. +The exploitation of this vulnerability could be triggered +via the parse function. +Fix CVE-2022-21222, CVE-2021-33587 (Closes: #989264, #1032188) + + -- Bastien Roucariès Wed, 01 Mar 2023 13:47:23 + + node-css-what (4.0.0-3) unstable; urgency=medium * Team

Bug#1032188: node-css-what: CVE-2022-21222/CVE-2021-33587

2023-03-01 Thread Bastien Roucariès
Package: node-css-what Version: 4.0.0-3 Severity: serious Tags: security Justification: security X-Debbugs-Cc: Debian Security Team Dear Maintainer, Find the minimal ReDoS fix for 4.0.0, checked with recheck Bastien>From eeb1fafd26a9f09114b6f8282a9569f99d52d716 Mon Sep 17 00:00:00 2001 From: =?

Bug#1031859: false positive of embedded expat library leads to ftp-master rejection

2023-02-26 Thread Bastien Roucariès
control: tags -1 + moreinfo Le dimanche 26 février 2023, 13:17:54 UTC Matthias Klose a écrit : Hi, > control: tags -1 -moreinfo > > On 25.02.23 15:14, Bastien Roucariès wrote: > > control: tags -1 +moreinfo > > Le vendredi 24 février 2023, 11:28:18 UTC Matthias Klose a

Bug#1031952: gettext: Missing source for an installed windows binary

2023-02-25 Thread Bastien Roucariès
Package: gettext Version: 0.21-11 Severity: serious Tags: ftbfs upstream Justification: DFSG #2 User: lintian-ma...@debian.org Usertags: source-is-missing X-Debbugs-Cc: ftpmas...@debian.org Hi, your package includes some files that seem to lack sources in preferred forms of modification: gettext-

Bug#1031859: false positive of embedded expat library leads to ftp-master rejection

2023-02-25 Thread Bastien Roucariès
control: tags -1 +moreinfo Le vendredi 24 février 2023, 11:28:18 UTC Matthias Klose a écrit : > Package: lintian > Version: 2.116.3 > Severity: serious > Tags: sid bookworm > > seen with the binary packages from > https://people.debian.org/~doko/tmp/ > > $ lintian -F python3.12_3.12.0~a5-1_amd64.

Bug#1023239: dracut: [regression] missing grep

2022-10-31 Thread Bastien Roucariès
Package: dracut Version: 056-3 Severity: critical Tags: patch upstream Justification: breaks the whole system Forwarded: https://github.com/dracutdevs/dracut/commit/79f9d9e1c29a9c8fc046ab20765e5bde2aaa3428 Dear Maintainer, grep is missing failling with lvm main partition. Could you apply patch

Bug#1020747: AM_PATH_PYTHON

2022-09-30 Thread Bastien Roucariès
control: reassign -1 automake control: affects -1 autoconf-archive Hi, The macro AM_PATH_PYTHON dos not support 3 level python version... The bug lie in automake not autoconf-archive Could be workarround by a little sed script in order remove micro version on graph tool side Bastien

Bug#1017513: isa-support: mktemp on /usr/lib and base64 encoded binary in preinst are evil

2022-08-17 Thread Bastien Roucariès
Source: isa-support Version: 7 Severity: grave Tags: patch Justification: causes non-serious data loss Dear Maintainer, mktemp could fail and base64 is preinst is not nice -- System Information: Debian Release: bookworm/sid APT prefers testing APT policy: (900, 'testing') Architecture: amd6

Bug#1017213: cross-toolchain-base: Patch for gcc11 support

2022-08-15 Thread Bastien Roucariès
Source: cross-toolchain-base Version: 59 Followup-For: Bug #1017213 Control: tags -1 + patch Dear Maintainer, Could you apply https://salsa.debian.org/toolchain-team/cross-toolchain- base/-/merge_requests/7 Thanks Rouca -- System Information: Debian Release: bookworm/sid APT prefers testin

Bug#1017213: Need gcc11

2022-08-15 Thread Bastien Roucariès
control: tags -1 + confirmed Need gcc11 ... Bastien /build/cross-toolchain-base-59.1/glibc-2.34/configure: line 2671: x86_64-linux- gnu-gcc-11: command not found configure:2673: $? = 127 configure: failed program was: | /* confdefs.h */ | #define PACKAGE_NAME "GNU C Library" | #define PACKAGE_TAR

Bug#1017083: bibledit: Some sources are not included in your package

2022-08-13 Thread Bastien Roucariès
Source: bibledit Version: 5.0.983-1 Severity: serious Tags: upstream ftbfs security Justification: DFSG #2 X-Debbugs-Cc: Debian Security Team , debian...@lists.debian.org Dear Maintainer, Your package includes some files that seem to lack sources in preferred forms of modification: # Several m

Bug#978051: Need it

2021-10-06 Thread Bastien Roucariès
Hi; I need it for gulp-wrap that is needed for a chai extension signature.asc Description: This is a digitally signed message part.

Bug#995722: loash: Vendoring should be removed

2021-10-04 Thread Bastien Roucariès
Source: src:node-lodash Version: 4.17.21+dfsg+~cs8.31.173-1 Severity: serious Justification: do not compile from source Dear Maintainer, The vendor directory should be emptied The debug version is compiled without source (lintian warn) and moreover the rest of file are already packaged grep -R

Bug#994974: node-define-property: Please deembed and fix vulnereability

2021-09-24 Thread Bastien Roucariès
Package: node-define-property Severity: serious Tags: security upstream fixed-upstream Justification: security bug Forwarded: https://github.com/jonschlinkert/define-property/pull/6 X-Debbugs-Cc: Debian Security Team Dear Maintainer, According to https://www.npmjs.com/advisories/1490 node-define

Bug#994720: nodejs: Please depends of sse2-support

2021-09-19 Thread Bastien Roucariès
Source: nodejs Severity: serious Tags: patch Justification: base arch Forwarded: https://chromium.googlesource.com/v8/v8.git/+/e825c4318eb2065ffdf9044aa6a5278635c36427 Dear Maintainer, libv8 need sse2 on i386 since 2017... I asked upstream better communication with us, but we must depends on ss

Bug#994703: nodejs: please documents deps or avoid it

2021-09-19 Thread Bastien Roucariès
Package: nodejs Version: 12.22.5~dfsg-2 Severity: serious Dear Maintainer, README.source should document the deps directory. It will be better to remove some libs from deps. Why libz is needed for node ? Could we push this plugin stuff to libz and so on. Acorn embdeded should be fixed by recent

Bug#994612: nodjes: Please fix nodejs debci regression

2021-09-18 Thread Bastien Roucariès
Package: nodjes Version: 12.22.5~dfsg-3 Severity: serious Dear Maintainer, Debci fail with against 12.22.5~dfsg-2 with: duration_ms: 0.293 severity: fail exitcode: 1 stack: |- assert.js:101 throw new AssertionError(obj); ^ AssertionError [ERR_ASSERTION]: Expected valu

Bug#994603: node-stringprep: FTBFS or build empty lib

2021-09-18 Thread Bastien Roucariès
Source: node-stringprep Severity: grave Tags: upstream Justification: renders package unusable Dear Maintainer, Trying to convert this package to arch:foreign due to an upstream error when we removed icu-config this package does not compile source, thus ship an empty lib.. I tried to get the sou

Bug#994451: golang-github-containers-common: secomp.json does not include newer syscall used by stable kernel/glibc on arm

2021-09-16 Thread Bastien Roucariès
Package: golang-github-containers-common Version: 0.33.4+ds1-1 Severity: critical Tags: upstream Forwarded: https://github.com/containers/common/commit/42d1db16bfc0dbaee5781d230dc2bcbaa0849c6e Control: fixed -1 0.42.1+ds1-1 Dear Maintainer, golang-github-containers-common in stable does not incl

Bug#993659: firefox-esr: FTBFS and embeded copy of code

2021-09-04 Thread Bastien Roucariès
Source: src:firefox-esr Version: FTBFS and embdeded copy Severity: serious Tags: upstream ftbfs Control: clone -1 -2 Control: affects -2 src:firefox Dear Maintainer, I could not found the source of the following files https://sources.debian.org/src/firefox- esr/78.13.0esr-1/devtools/client/debugg

Bug#993301: prototypejs: FTBFS

2021-08-30 Thread Bastien Roucariès
Source: prototypejs Severity: serious Justification: 4 Dear Maintainer, The source is https://github.com/prototypejs/prototype/tree/master and need rake for building... So FTBFS Bastien

Bug#992150: Please allow symlink in system extension

2021-08-16 Thread Bastien Roucariès
Followup-For: Bug #992150 Control: clone -1 src:firefox-esr

Bug#992150: Please allow symlink in system extension

2021-08-13 Thread Bastien Roucariès
Package: firefox Version: 57.0.0 Severity: serious Tags: upstream Justification: Policy 4.13 Forwarded: https://bugzilla.mozilla.org/show_bug.cgi?id=1420286 X-Debbugs-Cc: pkg-javascript-de...@lists.alioth.debian.org Control: tags -1 + security Hi, By default firefox does not allow symlink in syst

Bug#991982: nano does not work with TERM unset

2021-08-10 Thread Bastien Roucariès
Le mardi 10 août 2021, 08:05:00 UTC Benno Schulenberg a écrit : > Op 09-08-2021 om 15:08 schreef Bastien Roucariès: > > nano work with TERM=dumb (but is strange but it work), > > For me, 'TERM=dumb nano somefile' does not work, not on a console, not > on an xterm, not

Bug#991982: nano does not work with TERM unset

2021-08-09 Thread Bastien Roucariès
Le dimanche 8 août 2021, 10:04:30 UTC Benno Schulenberg a écrit : > > $env -i nano > > command fail because TERM is unset > > I can work around an unset TERM. But what if TERM=="" or TERM=="nonsense"? > Checking whether TERM is a valid terminal name goes too far, in my opinion. > > Also, is the

Bug#991982: nano does not work with TERM unset

2021-08-09 Thread Bastien Roucariès
Le dimanche 8 août 2021, 14:57:42 UTC Bastien Roucariès a écrit : > Le dimanche 8 août 2021, 10:04:30 UTC Benno Schulenberg a écrit : > > > $env -i nano > > > command fail because TERM is unset > > > > I can work around an unset TERM. But what if TERM=="&

  1   2   3   >