Tuesday, 2024-07-23

opendevreviewJeremy Stanley proposed openstack/ossa master: Add OSSA-2024-002 (CVE-2024-40767)  https://review.opendev.org/c/openstack/ossa/+/92473514:03
fungiprometheanfire: tonyb: JayF: rosmaita: ^14:04
JayF+214:09
fungii've also got the advisory e-mails based on the rst version of that queued up and ready to send at the top of the hour14:17
priteauWill there be patches available for Zed and Yoga?14:22
fungii think zigo made some backports for debian, but i don't recall what versions exactly14:23
fungiunmaintained/yoga and unmaintained/zed branches are past end of maintenance, so project maintainers aren't expected to provide patches for those14:24
fungii think mnaser did backports of ossa-2024-001 to unmaintained/zed, so may be working on similar for this14:25
fungii'm going to self-approve 924735 so the site will hopefully have the published copy at the same time as i send the announcements14:29
opendevreviewMerged openstack/ossa master: Add OSSA-2024-002 (CVE-2024-40767)  https://review.opendev.org/c/openstack/ossa/+/92473514:38
fungihttps://security.openstack.org/ has it now, so we're all set for the announcements to go out in 15 minutes. i've also notified mitre that the corresponding cve entry can be switched to public14:45
fungifire in the hole!15:00
rosmaitasorry i missed the shout out, but  924735 LGTM15:47
zigopriteau: I backported from caracal all the way to victoria, all is in http://osbpo.debian.net15:49
priteauzigo: thanks. I managed to do a clean backport to yoga as well by pulling the iso file format inspector patch series15:51

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!