Re: [Kolab-devel] Erlang security update breaks guam on Debian 10
Lennart <[email protected]> Mon, 17 Jul 2023 18:44:54 +0200
| Newsgroups | gmane.comp.kde.devel.kolab |
|---|---|
| Message-ID | <cd1cd310-b62a-e82d-2e41-c0d84b8b9d6b__13475.9843860351$1689612662$gmane$org@ackermans.ch> |
This is a multi-part message in MIME format. --===============8251025196589689235== Content-Type: multipart/alternative; boundary="------------P01OJjKt2wHOktPW2niMg3kl" Content-Language: en-GB This is a multi-part message in MIME format. --------------P01OJjKt2wHOktPW2niMg3kl Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit Update: the major upgrade was intentional. https://lists.debian.org/debian-lts/2023/07/msg00028.html I think rebuilding guam based on the Debian security version of Erlang is the most responsible choice. Even if something like this happens again in the future it might be better that things break than that we keep security vulnerabilities. Best, Lennart On 17-07-2023 15:36, Lennart Ackermans wrote: > > > > On 2023-07-17 07:12, Christian Mollekopf wrote: > >> >> I'd rather have it bundled than wake up to our packages no longer >> starting because the upstream erts package changed, so for unbundling >> we need to figure which erts version to pin first IMO. >> > Major updates like this recent erlang security update normally don't > happen on stable Debian releases. The erlang package maintainer thinks > this was probably a mistake by the Debian LTS team (email > communication). If it is, it might be reverted. If it was intentional, > that's a strange decision and probably not something that will be > repeated. To be sure I asked on the Debian LTS mailing list. Should > appear here: https://lists.debian.org/debian-lts/2023/07/threads.html. > Best, > Lennart > > _______________________________________________ > devel mailing list > [email protected] > https://lists.kolab.org/mailman/listinfo/devel --------------P01OJjKt2wHOktPW2niMg3kl Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <html> <head> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DUTF= -8"> </head> <body text=3D"#000000" bgcolor=3D"#FFFFFF"> <p>Update: the major upgrade was intentional. <a class=3D"moz-txt-link-freetext" href=3D"https://lists.debian.org= /debian-lts/2023/07/msg00028.html">https://lists.debian.org/debian-lts/20= 23/07/msg00028.html</a></p> <p>I think rebuilding guam based on the Debian security version of Erlang is the most responsible choice. Even if something like this happens again in the future it might be better that things break than that we keep security vulnerabilities.</p> <p>Best,</p> <p>Lennart<br> </p> <div class=3D"moz-cite-prefix">On 17-07-2023 15:36, Lennart Ackermans wrote:<br> </div> <blockquote type=3D"cite" cite=3D"mid:[email protected]"> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DU= TF-8"> <p><br> </p> <p><br> </p> <p id=3D"v1reply-intro">On 2023-07-17 07:12, Christian Mollekopf wrote:</p> <blockquote type=3D"cite" style=3D"padding: 0 0.4em; border-left: #1010ff 2px solid; margin: 0"> <div class=3D"v1pre"><br> I'd rather have it bundled than wake up to our packages no longer starting because the upstream erts package changed, so for unbundling we need to figure which erts version to pin first IMO.<br> <br> </div> </blockquote> <div class=3D"v1pre">=C2=A0</div> <div class=3D"v1pre">Major updates like this recent erlang security update normally don't happen on stable Debian releases. The erlang package maintainer thinks this was probably a mistake by the Debian LTS team (email communication). If it is, it might be reverted. If it was intentional, that's a strange decision and probably not something that will be repeated. To be sure I asked on the Debian LTS mailing list. Should appear here: <a href=3D"https://lists.debian.org/debian-lts/2023/07/threads.htm= l" moz-do-not-send=3D"true" class=3D"moz-txt-link-freetext">https:= //lists.debian.org/debian-lts/2023/07/threads.html</a>.</div> <div class=3D"v1pre">=C2=A0</div> <div class=3D"v1pre">Best,</div> <div class=3D"v1pre">Lennart</div> <br> <fieldset class=3D"moz-mime-attachment-header"></fieldset> <pre class=3D"moz-quote-pre" wrap=3D"">____________________________= ___________________ devel mailing list <a class=3D"moz-txt-link-abbreviated" href=3D"mailto:[email protected]= g">[email protected]</a> <a class=3D"moz-txt-link-freetext" href=3D"https://lists.kolab.org/mailma= n/listinfo/devel">https://lists.kolab.org/mailman/listinfo/devel</a></pre= > </blockquote> </body> </html> --------------P01OJjKt2wHOktPW2niMg3kl-- --===============8251025196589689235== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ devel mailing list [email protected] https://lists.kolab.org/mailman/listinfo/devel --===============8251025196589689235==--