[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#825695: marked as done (udd todo: List unsolved security issues in the TODO list?)



Your message dated Sat, 2 Jul 2016 21:04:13 +0200
with message-id <20160702190413.GA3094@xanadu.blop.info>
and subject line Re: Bug#825695: udd todo: List unsolved security issues in the TODO list?
has caused the Debian Bug report #825695,
regarding udd todo: List unsolved security issues in the TODO list?
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
825695: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=825695
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Package: qa.debian.org
Severity: wishlist
User: qa.debian.org@packages.debian.org
Usertags: udd
X-Debbugs-CC: security-tracker@packages.debian.org

As bug #660170 is solved and the information from the security tracker
was made available in UDD, would it be an idea to list the unfixed
security issues in the TODO list, similar to RC bugs?

I'm not quite sure how to implement it, but suspect something like this
SQL search can give an idea about the information I would like to have
shown:
  
  select * from security_issues_releases where source in (select source from sources where maintainer_email = 'pere@debian.org' or uploaders like '%pere@debian.org%') and status != 'resolved';

The idea is to get something similar to
<URL: https://security-tracker.debian.org/tracker/source-package/vorbis-tools >
only per developer instead of per package, to show up in the TODO list,
so I would be more aware of the unsolved issues.

-- 
Happy hacking
Petter Reinholdtsen

--- End Message ---
--- Begin Message ---
On 10/06/16 at 09:59 +0200, Petter Reinholdtsen wrote:
> 
> Control: tags -1 + patch
> 
> [Paul Wise]
> > Not sure why they are showing up in the UDD database, but the
> > explanations are at the bottom of this:
> >
> > https://security-tracker.debian.org/tracker/status/release/stable
> 
> Right.  I guess that need to be fixed in the importer, if it should be
> changed.  I'm not trying to address this here.
> 
> Anyway, I found a way to test the the code, and fixed a few typos.  The
> following patch work and include open security issues in the Todo list.
> Is this OK to put into production?

This has been committed and deployed on June 11th AFAIK.

- Lucas

--- End Message ---

Reply to: