#1012047 bullseye-pu: package composer/2.0.9-2+deb11u1

#1012047#5
Date:
2022-05-29 10:23:08 UTC
From:
To:
[ Reason ]

I’d like to address CVE-2022-24828 that has been tagged as no-dsa. Some
people may also wish to see #989315 fixed (it was reported twice), and
the fix is trivial, so I’m proposing a fix for it too.

[ Impact ]

The security fix is worth it, the GitHub token pattern fix is useful for
people using this feature.

[ Tests ]

I had to also checkout a file used for the updated testsuite that
passes. I’m not using the Github feature, but the regex fix looks pretty
obvious.

[ Risks ]

I’ve also provided the diffoscope output, showing probably better the
trival changes.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

Regards

Thanks in advance.

David

#1012047#10
Date:
2022-06-26 17:19:33 UTC
From:
To:
Control: tags -1 + confirmed

Please go ahead.

Regards,

Adam

#1012047#17
Date:
2022-07-01 15:22:31 UTC
From:
To:
package release.debian.org
tags 1012047 = bullseye pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye.

Thanks for your contribution!

Upload details
==============

Package: composer
Version: 2.0.9-2+deb11u1

Explanation: fix code injection issue [CVE-2022-24828]; update GitHub token pattern

#1012047#22
Date:
2022-07-01 15:22:31 UTC
From:
To:
package release.debian.org
tags 1012047 = bullseye pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye.

Thanks for your contribution!

Upload details
==============

Package: composer
Version: 2.0.9-2+deb11u1

Explanation: fix code injection issue [CVE-2022-24828]; update GitHub token pattern

#1012047#27
Date:
2022-07-09 10:47:43 UTC
From:
To:
(re-sending with fixed bug numbers)

Hi,

The updates discussed in these bugs were included in today's bullseye
point release.

Regards,

Adam