[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

October Report



Hi,

October 2017 was my 14th month as a payed Debian LTS contributor.

I was allocated 20 hours. I have spent all of them doing the following
tasks:

* Organize libav support in Wheezy, test and upload libav update
  6:0.8.21-0+deb7u1 (DLA 1142-1).

  Despite the higher activity around libav LTS support these last weeks,
  the backlog is still quite high (42 CVEs with status "affected" or
  "undetermined" in the tracker). The next update is scheduled in two
  weeks, with the goal of addressing as many vulnerabilities as reasonably
  possible until the end of Wheezy LTS support.

* Prepare, test and upload ming 1:0.4.4-1.1+deb7u4 (DLA 1133-1).

  This upload has been quite a lot of work since I've been writing all
  patches by myself (6 CVEs fixed). Fortunately, upstream was very
  responsive and reviewed/accepted all pull requests.

  You can find more informations about affected issues here:

  https://github.com/libming/libming/issues/76
  https://github.com/libming/libming/issues/82
  https://github.com/libming/libming/issues/83

* Prepare next security update for ming (1:0.4.4-1.1+deb7u5).

  Not uploaded yet, I am still working on patches for further issues.

  Similarily to 1:0.4.4-1.1+deb7u4, I am writing all patches by
  myself.
  
  You can find more informations about affected issues here:

  https://github.com/libming/libming/issues/85
  https://github.com/libming/libming/issues/86
  https://github.com/libming/libming/issues/78

Next month I am planning to continue my work on ming, with the goal of
addressing all remaining issues in a near future.

Best Regards,
 Hugo

-- 
             Hugo Lefeuvre (hle)    |    www.owl.eu.com
4096/ 9C4F C8BF A4B0 8FC5 48EB 56B8 1962 765B B9A8 BACA

Attachment: signature.asc
Description: PGP signature


Reply to: