[Secure-testing-team] what else needs a DTSA right now?

Steve Langasek vorlon at debian.org
Wed Aug 31 21:29:45 UTC 2005


On Wed, Aug 31, 2005 at 09:49:06AM -0400, Joey Hess wrote:
> Steve Langasek wrote:
> > There's zlib1g/1:1.2.2-4.sarge.2 in t-p-u on spohr for 10 of 11
> > architectures; getting the s390 binaries accepted requires ftp-master
> > intervention because a race condition was hit with the upload, but once
> > that's done, we can push the same DSA binaries directly into testing...

> Hmm, if pushing DSA bins to testing is an option,

Yes, it is an option; the testing/tpu-approved/security-team file was
created on ftp-master so that the security team could do this directly,
but that file dates to Jul 2002, so I'm not sure it has any real data in
it and certainly nothing recent.

You also have access to do this in your own hints file, though, using an
"approve" hint.

> you could also do it with mozilla and firefox, which haven't changed
> since sarge in there.

Same problem:  because of the FTBFS in unstable on alpha/arm/ia64, the
mozilla security updates for those arches were not accepted into
proposed-updates/t-p-u.

And firefox is also missing arm.

But if someone NMUed mozilla in unstable, the unaccepted binaries should
make their way back into t-p-u and could be approved.

-- 
Steve Langasek                   Give me a lever long enough and a Free OS
Debian Developer                   to set it on, and I can move the world.
vorlon at debian.org                                   http://www.debian.org/
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: Digital signature
Url : http://lists.alioth.debian.org/pipermail/secure-testing-team/attachments/20050831/758b7ef3/attachment.pgp


More information about the Secure-testing-team mailing list