[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#959723: RM: matrix-synapse/0.99.2-6 -- ROM; security issues; obsolete version



Package: release.debian.org
Severity: normal
User: release.debian.org@packages.debian.org
Usertags: rm

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Hi,

Synapse 0.99 was never meant to be a properly usable release in buster,
and it was only included as some sort of a plug to make upgrades a tiny
bit easier for users — they were supposed to upgrade the package to the
version from backports almost immediately.

However, the time when this version was usable has definitely passed. It
has a bunch of security issues fixed in the newer releases, and the
effort of porting them back is significant, while most probably everyone
running synapse on buster is on the version from backports or the
version from the upstream.

Please remove matrix-synapse from buster only.

- -- 
Cheers,
  Andrej

-----BEGIN PGP SIGNATURE-----

iQFIBAEBCAAyFiEEeuS9ZL8A0js0NGiOXkCM2RzYOdIFAl6wGQYUHGFuZHJld3No
QGRlYmlhbi5vcmcACgkQXkCM2RzYOdIOBQgApcBo4SaRyku51aDRpwXOO4NIDYU5
OSYiz9T5/zIcfemivOt52ZieEunwA5aq2xNApkhuqVGGi5Y3n8MPgTWC9ZNDLUjv
iCGx9UKEFJWXYCyrk31nqs+Ljazpg3CU2wGbkdilHb5RX6/QWQU5Rn+OzKITxOfI
+0C+7+LqAVNDE5G1J2sZqrIqx0kCEaOeWOYHFI00yfENxiYWmM2nNUz+vpwYW3jW
MI0v7baYIxc54vguWTh/LWFh6ScgMRwoEJe1Q2LpEOCyjCuN44e8l57VLjrFXt/c
OQl2NAQT0JtHAyyrfjl+AsdXtLecy8gCiST4pLGCjVVGxLvlcP0UKJmTow==
=gXcO
-----END PGP SIGNATURE-----

Reply to: