Bug#963764: [Pkg-javascript-devel] Bug#963764: Bug#963764: node-node-sass: uses embedded old security-buggy libsass

2020-07-08 Thread merkys
Hello, On 2020-07-08 18:46, Jonas Smedegaard wrote: > I don't want packages removed either - and for this one specifically, I > very much look forward to having mermaid in Debian - cool stuff!) I also would be unhappy to see node-node-sass removed from Debian, but I subscribe to Jonas's opinion

Bug#963764: [Pkg-javascript-devel] Bug#963764: Bug#963764: node-node-sass: uses embedded old security-buggy libsass

2020-07-08 Thread Jonas Smedegaard
Quoting Nilesh Patra (2020-07-08 17:13:49) > On Wed, 8 Jul 2020, 20:38 Jonas Smedegaard, wrote: > > If we expect this package to evolve badly, then we should *not* keep > > an embedded copy of libsass, but instead remove this package and all > > its reverse dependencies, because libsass has been

Bug#963764: [Pkg-javascript-devel] Bug#963764: Bug#963764: node-node-sass: uses embedded old security-buggy libsass

2020-07-08 Thread Nilesh Patra
On Wed, 8 Jul 2020, 20:38 Jonas Smedegaard, wrote: > Quoting Nilesh Patra (2020-07-08 17:00:01) > > On Wed, 8 Jul 2020, 20:22 Jonas Smedegaard, wrote: > > > > > Quoting Nilesh Patra (2020-07-08 16:26:34) > > > > On Wed, 8 Jul 2020, 19:30 Jonas Smedegaard, wrote: > > > > > Please strongly consid

Bug#963764: [Pkg-javascript-devel] Bug#963764: Bug#963764: node-node-sass: uses embedded old security-buggy libsass

2020-07-08 Thread Jonas Smedegaard
Quoting Nilesh Patra (2020-07-08 17:00:01) > On Wed, 8 Jul 2020, 20:22 Jonas Smedegaard, wrote: > > > Quoting Nilesh Patra (2020-07-08 16:26:34) > > > On Wed, 8 Jul 2020, 19:30 Jonas Smedegaard, wrote: > > > > Please strongly consider to not only make the package link with > > > > system-shared

Bug#963764: [Pkg-javascript-devel] Bug#963764: Bug#963764: node-node-sass: uses embedded old security-buggy libsass

2020-07-08 Thread Nilesh Patra
On Wed, 8 Jul 2020, 20:22 Jonas Smedegaard, wrote: > Quoting Nilesh Patra (2020-07-08 16:26:34) > > On Wed, 8 Jul 2020, 19:30 Jonas Smedegaard, wrote: > > > Please strongly consider to not only make the package link with > > > system-shared libsass, but also repackage upstream tarball with > > >

Bug#963764: [Pkg-javascript-devel] Bug#963764: Bug#963764: node-node-sass: uses embedded old security-buggy libsass

2020-07-08 Thread Jonas Smedegaard
Quoting Nilesh Patra (2020-07-08 16:26:34) > On Wed, 8 Jul 2020, 19:30 Jonas Smedegaard, wrote: > > Please strongly consider to not only make the package link with > > system-shared libsass, but also repackage upstream tarball with > > embedded code copy removed, to ensure not accidentally using

Bug#963764: [Pkg-javascript-devel] Bug#963764: Bug#963764: node-node-sass: uses embedded old security-buggy libsass

2020-07-08 Thread Nilesh Patra
Hi, On Wed, 8 Jul 2020, 19:30 Jonas Smedegaard, wrote: > Quoting mer...@debian.org (2020-07-08 15:13:06) > > The upstream has updated the libsass support to 3.6.3 [1], it's just > > not released yet. I have successfully used head of their git > > repository to build node-node-sass without the em

Bug#963764: [Pkg-javascript-devel] Bug#963764: node-node-sass: uses embedded old security-buggy libsass

2020-07-08 Thread Jonas Smedegaard
Quoting mer...@debian.org (2020-07-08 15:13:06) > The upstream has updated the libsass support to 3.6.3 [1], it's just > not released yet. I have successfully used head of their git > repository to build node-node-sass without the embedded libsass copy > (there were a couple of failing mocha tes

Bug#963764: node-node-sass: uses embedded old security-buggy libsass

2020-07-08 Thread merkys
Control: tags 963764 + help Hello, The upstream has updated the libsass support to 3.6.3 [1], it's just not released yet. I have successfully used head of their git repository to build node-node-sass without the embedded libsass copy (there were a couple of failing mocha tests, however). I could

Bug#963764: node-node-sass: uses embedded old security-buggy libsass

2020-06-26 Thread Jonas Smedegaard
Package: node-node-sass Version: 4.13.1-2 Severity: serious Tags: security -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 node-node-sass ships with an old release of libsass. Since Debian release 4.13.1-2 this is explicitly used (uncertain if previously it might alos accidentally be used). Lib