[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Incomplete UDD import of CPE info from upstream/metadata?



Le Fri, Dec 16, 2016 at 07:59:53AM +0800, Paul Wise a écrit :
> On Thu, Dec 15, 2016 at 8:17 PM, Petter Reinholdtsen wrote:
> 
> > I was looking at the automatic CVE tracking a bit today, and hoped to
> > figure out which packages had the CPE field already in their
> > debian/upstream/metadata file.  But according to UDD there are none:
> 
> I expect that is because UMEGAYA is not working right now:
> 
> https://wiki.debian.org/UpstreamMetadata
> 
> > Help! there is a bug that I do not manage to solve by myself. -- Charles
> > https://lists.debian.org/debian-qa/2014/06/msg00022.html

Indeed, I got no help and was stuck in the end.  I should have retired the
service promptly but did not find time, sorry for this.

I still wish I would rewrite it in a different language (for the fun, I would
like to use the opportunity to practice Haskell), but I also did not find time(*).

Looking at my work and family commitments, I see it unlikely to make
signigicant progress in the next months.

> Also, please note that UMEGAYA was only tracking metadata files in VCS
> repos, not the ones in the archive and there are definitely some in
> the archive that aren't in any VCS.

Maybe now with dgit the problem is kind of solved :)

Have a nice day,

(*) You might wonder, how come I sent recently a longish email on -project, and
then claim that I have no time do important work ?  Opinion emails can be
written slowly piece by piece while commuting in the train, and thinking about
what to write can be done while walking, etc.  For other tasks like working on
doing or undoing UMEGAYA, I need to secure some free time where I can
concentrate, and this has become extremely rare in the past months. 

-- 
Charles Plessy
Debian Med packaging team,
http://www.debian.org/devel/debian-med
Tsurumi, Kanagawa, Japan


Reply to: