Bug#555679: release.debian.org: consider forcing viewvc/1.0.9-1 into squeeze

View: New views
1 Messages — Rating Filter:   Alert me  

Bug#555679: release.debian.org: consider forcing viewvc/1.0.9-1 into squeeze

by Simon McVittie-7 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Package: release.debian.org
Severity: normal

viewvc/1.0.9-1 fixes grave security bug #545779, but can't migrate to squeeze
because it would make gforge-plugin-scmsvn (from src:gforge) uninstallable.
This is because g-p-s still depends on the viewcvs transitional package,
which was already transitional in lenny and no longer exists in sid. I filed
#552524 against g-p-s.

Please consider pushing viewvc/1.0.9-1 into squeeze anyway; this would make
g-p-s uninstallable there (as a workaround, users could take the viewcvs
transitional binary package from lenny). If I'm reading the docs correctly,
this hint would be appropriate:

    # breaks gforge-plugin-scmsvn (#552524) but fixes security bug (#545779)
    force viewvc/1.0.9-1

Regards,
    Simon


signature.asc (809 bytes) Download Attachment