Re: sbuild and dpkg-checkbuilddeps

2025-02-13 Thread Johannes Schauer Marin Rodrigues
Hi, you might want to consider bringing up what you think are problems with sbuild on on the Debian BTS of sbuild instead of d-devel unless you think that this topic deserves wider discussion. I put the relevant bug in CC. Maybe drop debian-devel@lists.debian.org unless you think that this issue d

sbuild and dpkg-checkbuilddeps

2025-02-13 Thread Scott Talbert
Hi, It seems that something changed in the last month or so with sbuild such that when building a package, it now seems to run dpkg-checkbuilddeps _outside_ the chroot and will fail all the build deps aren't installed. Is there a way to avoid this behavior, other than by using --no-clean-sou

Bug#1095934: ITP: golang-github-bougou-go-ipmi -- Pure Go IPMI client library

2025-02-13 Thread Daniel Swarbrick
Package: wnpp Severity: wishlist Owner: Daniel Swarbrick X-Debbugs-Cc: debian-devel@lists.debian.org, debian...@lists.debian.org * Package name: golang-github-bougou-go-ipmi Version : 0.7.2-1 Upstream Contact: Bougou Nisou * URL : https://github.com/bougou/go-ipmi * Li

Re: Need advice on coordinating libkdumpfile update and introducing pykdumpfile

2025-02-13 Thread Michel Lind
On Thu, Feb 13, 2025 at 03:21:04PM -0700, Soren Stoutner wrote: > Michel, > > On Thursday, February 13, 2025 2:36:26 PM MST Michel Lind wrote: > > Ah, OK, so these uploads all require FTP master review right? > > > > - soname bump to 0.5.5 in experimental > > - initial upload of the new pykdumpfi

Re: Need advice on coordinating libkdumpfile update and introducing pykdumpfile

2025-02-13 Thread Soren Stoutner
Michel, On Thursday, February 13, 2025 2:36:26 PM MST Michel Lind wrote: > Ah, OK, so these uploads all require FTP master review right? > > - soname bump to 0.5.5 in experimental > - initial upload of the new pykdumpfile in experimental > - dropping python bindings in experimental > - 0.5.5 with

Re: Need advice on coordinating libkdumpfile update and introducing pykdumpfile

2025-02-13 Thread Michel Lind
On Thu, Feb 13, 2025 at 09:23:49AM +0100, Emilio Pozuelo Monfort wrote: > On 12/02/2025 23:57, Michel Lind wrote: > > Dear all, > > > > libkdumpfile has recently released version 0.5.5, which despite the > > version number, actually contains an soname bump from 0.5.4 > > > > https://github.com/pt

Re: Packages with a history of security issues and whose packaged version is not up to date

2025-02-13 Thread Holger Levsen
On Thu, Feb 13, 2025 at 08:34:07PM +0100, Jonas Smedegaard wrote: > Hi Santiago, > It would probably be helpful to also share the result of somehow running > the compiled list through dd-list, to raise attention for involved > maintainers. I want to say: yes. :) please do. -- cheers, Ho

Re: Packages with a history of security issues and whose packaged version is not up to date

2025-02-13 Thread Paul Gevers
Hi, On 13-02-2025 20:21, Santiago Ruano Rincón wrote: Any thoughts? You might also want to somehow take activity on the package into account. E.g. cacti (that I am nearly the only uploader for) has seen an update for CVE's only last week. I don't think I need (nor would I appreciate) more

Re: Filesystem snapshotting in dpkg (was Re: A 2025 NewYear present: make dpkg --force-unsafe-io the default?)

2025-02-13 Thread Vincent Danjean
Hi, Le 28/12/2024 à 15:21, Guillem Jover a écrit : In this case (filesystem snapshotting), I do think dpkg is (currently at least) really the wrong place, for at least the following reasons: In addition, I do not see how snapshotting of full FS can be correctly supported, unless all other

Re: Packages with a history of security issues and whose packaged version is not up to date

2025-02-13 Thread Jeremy Stanley
On 2025-02-13 16:21:10 -0300 (-0300), Santiago Ruano Rincón wrote: [...] > So, this is a call for comments: is this kind of package list useful? [...] The main problem I see is that the list includes projects who backport security fixes to stable branches, so for example python-keystonemiddleware

Re: What is going on with atomics?

2025-02-13 Thread Vincent Danjean
Le 12/02/2025 à 05:57, Simon Richter a écrit : Hi, On 2/12/25 13:38, Johannes Schauer Marin Rodrigues wrote: ["DSO missing from command line"] I suspect that the problem is the order in which the -latomic is added to the linker flags? Yes. Because if instead of target_link_options() with

Re: Packages with a history of security issues and whose packaged version is not up to date

2025-02-13 Thread Jonas Smedegaard
Hi Santiago, Quoting Santiago Ruano Rincón (2025-02-13 20:21:10) > Here attached you can find a list of packages that have ever had a > security issue **and** whose packaged version is not "up to date", > according to the uscan results. It is sorted by the number of currently > open CVEs in sid (t

Packages with a history of security issues and whose packaged version is not up to date

2025-02-13 Thread Santiago Ruano Rincón
Dear Debian fellows, I am writing this email under the hypothesis that having the latest (or longest supported) upstream version in the next release will: 1. make it easier to provide security support during the whole release lifecycle, and 2. it will be useful for users, as they could have the la

Bug#1095906: ITP: ergochat-ldap -- LDAP authentication plugin for Ergo IRC server

2025-02-13 Thread Martina Ferrari
Package: wnpp Severity: wishlist Owner: Martina Ferrari * Package name: ergochat-ldap Version : 0.0.1-1 Upstream Author : Shivaram Lingamneni * URL : https://github.com/ergochat/ergo-ldap * License : Apache-2.0 Programming Lang: Go Description : LDAP a

Re: Need advice on coordinating libkdumpfile update and introducing pykdumpfile

2025-02-13 Thread Emilio Pozuelo Monfort
On 12/02/2025 23:57, Michel Lind wrote: Dear all, libkdumpfile has recently released version 0.5.5, which despite the version number, actually contains an soname bump from 0.5.4 https://github.com/ptesarik/libkdumpfile/releases/tag/v0.5.5 See e.g. the relevant Fedora packaging change https://s