[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: RFS: jffi-1.2.7 and jenkins-1.565.3-4



On 30 Mar 2015, at 7:37 pm, Emmanuel Bourg <ebourg@apache.org> wrote:
> 
> Le 30/03/2015 08:23, Potter, Tim (Cloud Services) a écrit :
>> On 9 Mar 2015, at 11:21 am, Miguel Landaeta <nomadium@debian.org> wrote:
>> 
>> Hi everyone.  I’m back in action again and keen to get jiffi and the other jnr-* modules uploaded to the archive.  I’ve made a small patch to the jenkins maven.rules file (and unapplied the previous patch I made a few weeks ago) so both jenkins and jffi are ready to be uploaded. 
>> 
>> I’m looking for a sponsor for these uploads now.  For Jenkins I built, installed and create a job to check that it wasn’t totally broken.  It looked OK as far as i could tell.
>> 
>> Currently working on a upstream version upgrade to fix the various security issues in bug 781223 but it’s not quite ready yet.
> 
> Hi Tim,
> 
> Thank you very much for helping with jenkins, this is a very challenging
> package. We may not be able to upload a new upstream release to unstable
> during the freeze. I haven't checked yet if the fixes could be
> backported to the version 1.565.3, but if we can't address them I'm
> affraid we would have to request the removal of Jenkins from Jessie.

Excellent point about unstable - what would you think about uploading to experimental instead?

It would be sad to have to remove Jenkins from Jessie but I think you’re right.  One of the CVE’s is marked as critical.  )-:


Tim.

Reply to: