Hi Salvatore,
On 26-03-2023 13:57, Salvatore Bonaccorso wrote:
redis is on the radar for that, recent uploads for unstable did fix
some (arguably no-dsa) CVEs. Redis is though not able to migrate to testing. Can you have a look and if the testing regressions are fase positives or to be ignore fill a unblock request for the release team?
Chris already did in bug 1030600, e.g. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1030600#30. I see redis
had another upload, which apparently doesn't trigger the autopkgtest failure in python-fakeredis.
Might be worth unblocking this version of redis if all upstream uploads can be justified.
The new version does not have any further regressions, as per https://qa.debian.org/excuses.php?package=redis. So I think that
would be welcome to resolve all the CVEs still affecting bookworm.
Chris, what is your take on it?
Dear all,
The new version does not have any further regressions, as per https://qa.debian.org/excuses.php?package=redis. So I think that
would be welcome to resolve all the CVEs still affecting bookworm.
Chris, what is your take on it?
Sorry for the delay in replying; some other things ate all my
bandwidth for considered thought in the last week or so.
To cut a long story short: yes, I agree that the ideal solution is to
unblock 5:7.0.10-1 (ie. the version currently in unstable) for
bookworm and release bookworm with that.
My gut feeling is that the 7.0.x branch will receive upstream-blessed
patches for security fixes for a little while. This would hopefully
make future DSAs relatively straightforward. (I doubt it will receive specific updates for the entirety of the bookworm release, alas, but
that's out of our control). Either way, it makes sense to release with
the latest version of the 7.0.x branch.
Salvatore, do you wish to request an unblock here (ie. of 5:7.0.10-1
in sid to override 5:7.0.7-1 in bookworm) or shall I? (Would it have
more weight if you did it?)
I do not think I have any special weight more on doing it ;-). If you
can ask with a bugreport for an unblock that would be great, thank you
Chris.
Sysop: | Keyop |
---|---|
Location: | Huddersfield, West Yorkshire, UK |
Users: | 465 |
Nodes: | 16 (3 / 13) |
Uptime: | 53:51:13 |
Calls: | 9,403 |
Calls today: | 3 |
Files: | 13,572 |
Messages: | 6,099,975 |
Posted today: | 1 |