Please merge moin 1.9.3-1 (main) from Debian unstable (main)

Bug #586518 reported by Clint Byrum
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
moin (Ubuntu)
Fix Released
Wishlist
Thierry Carrez

Bug Description

Should not proceed until MIR's are completed to allow reverting most of the ubuntu delta (fckeditor must still be demoted to suggests, and python-xml should still be removed):

MIR's:

https://bugs.launchpad.net/ubuntu/+source/mod-wsgi/+bug/566537
https://bugs.launchpad.net/ubuntu/+source/python-werkzeug/+bug/586489
https://bugs.launchpad.net/ubuntu/+source/xappy/+bug/586491
https://bugs.launchpad.net/ubuntu/+source/parsedatetime/+bug/586492

Changed in moin (Ubuntu):
assignee: nobody → Clint Byrum (clint-fewbar)
status: New → In Progress
description: updated
Lorenzo De Liso (blackz)
Changed in moin (Ubuntu):
importance: Undecided → Wishlist
Revision history for this message
Artur Rona (ari-tczew) wrote :

Any progress on it?

Revision history for this message
Clint Byrum (clint-fewbar) wrote :

Artur, this is still waiting on evaluation of the dependencies that aren't in main. I'm confident it will happen soon though.

Revision history for this message
FranklinPiat (fpiat) wrote :

FYI, MoinMoin 1.9.3 should enter unstable soon. it contains security fixes.

Revision history for this message
Clint Byrum (clint-fewbar) wrote :

Updating title, as debian has been updated. 1.9.3 does, indeed, contain security fixes.

mod_wsgi has been promoted to main, but still waiting on werkzeug, zappy, and parsedatetime.

summary: - Please merge moin 1.9.2-3 (main) from Debian unstable (main)
+ Please merge moin 1.9.3-1 (main) from Debian unstable (main)
Revision history for this message
Clint Byrum (clint-fewbar) wrote :

All deps have passed MIR, so I'm proceeding with the merge. However, I am a bit stuck now because of problems with the automated import process...

http://package-import.ubuntu.com/status/moin.html#2010-02-22 01:26:04.345632

Revision history for this message
Clint Byrum (clint-fewbar) wrote :

manual merge completed, contained in linked branch/merge proposal.

Changed in moin (Ubuntu):
status: In Progress → Confirmed
assignee: Clint Byrum (clint-fewbar) → nobody
Thierry Carrez (ttx)
Changed in moin (Ubuntu):
assignee: nobody → Thierry Carrez (ttx)
status: Confirmed → In Progress
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package moin - 1.9.3-1ubuntu1

---------------
moin (1.9.3-1ubuntu1) maverick; urgency=low

  * Merge from Debian unstable (LP: #586518). Based on work by Stefan Ebner.
    Remaining changes:
   - Remove python-xml from Suggests field, the package isn't anymore in
     sys.path.
   - Demote fckeditor from Recommends to Suggests; the code was previously
     embedded in moin, but it was also disabled, so there's no reason
     for us to pull this in by default currently. Note: fckeditor has a
     number of security problems and so this change probably needs to be
     carried indefinitely.

moin (1.9.3-1) unstable; urgency=low

  * New upstream release.

  [ Frank Lin PIAT ]
  * Build-Depends on python rather than python-dev.
    Closes: bug#576426.
  * Fix location of README.Migration in NEWS file.
  * Install upstream's docs/REQUIREMENTS file.
  * Add manpage moin(1).
  * Drop lintian override for test.wsgi: no longer executable.
  * Add lintian override for no-doc-base-registration.
  * Install the desktop edition sample config files.
  * Fix werkzeug-0.6 http redirect incompatibility.
    Closes: bug#579189.
  * Improve DEP3 header for patch fix_werkzeug_0.6_http_redirect
  * Fix werkzeug-0.6 xmlxpc incompatibility.
    Closes: bug#580186.

  [ Jonas Smedegaard ]
  * Fix conditionally append version in hash-bang of Python scripts
    (relevant only on systems where default Python version is
    unsupported - i.e. highly unlikely to have caused real trouble
    anywhere). Tighten build-dependency on cdbs to versions providing
    new variable name. Rephrase related comment.
  * Drop files section in copyright file for no longer shipped CDBS
    snippet.
  * Fix append version to python dependency if using non-default
    version.
  * Tidy rules file: move variable below cdbs inclusions, and improve
    some comments.
  * Drop patches applied in upstream 0.9.3 release. Refresh patches.
  * Tighten build-dependency on cdbs.
  * Bump Policy compliance to Standards-Version 3.9.1.

moin (1.9.2-3) unstable; urgency=high

  [ Frank Lin PIAT ]
  * Add patch to fix CVE-2010-0828: XSS in Despam page.
    Closes: 575995, thanks to Jamie Strandboge (Ubuntu).

  [ Jakub Wilk ]
  * Fix htdocs symlink, when compiled with python2.6.
    Closes: bug#557956.

  [ Jonas Smedegaard ]
  * Drop local package-relations.mk snippet, now in main cdbs package.
  * Unfuzz and refresh patches (with quilt compacting options
    --no-timestamps --no-index -pab).
  * Add DEP3 header to patch "CVE-2010-0828.patch".
  * Stop suppressing optional build-dependencies: we need recent cdbs
    anyway (to not complicate packaging with a local CDBS snippet) so
    cannot please backporters anyway.
  * Build-depend on devscripts and dh-buildinfo, and tighten build-
    dependency on cdbs, due to above changes.
 -- Clint Byrum <email address hidden> Wed, 11 Aug 2010 12:35:34 -0700

Changed in moin (Ubuntu):
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.