Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Please create a new upstream release #354

Closed
pkern opened this issue Oct 17, 2022 · 9 comments
Closed

Please create a new upstream release #354

pkern opened this issue Oct 17, 2022 · 9 comments

Comments

@pkern
Copy link

pkern commented Oct 17, 2022

There are various fixed CVEs in the repository (see e.g. Debian bug #1014977 for a list). Would it be possible to cut a new (tested) upstream release for inclusion into distributions?

For what it's worth there are also some older unfixed CVEs as well per Debian bug #1004963. (Aside from the recent flurry of even more fuzzing related bugs.)

Thanks!

@fancycode
Copy link
Member

There is a release 1.0.9 that contains the latest fixes for which I'm currently updating the packaging at "https://salsa.debian.org/multimedia-team/libde265".

@farindk will release another version once more fixes are available.

@farindk
Copy link
Contributor

farindk commented Jan 27, 2023

I've just released v1.0.10 which fixes all known and reproducible issues.

@fancycode Could you please build the Debian package for this as they would like to have this in the next Debian stable release in two weeks: #372 (comment)
There are no API changes.

@farindk
Copy link
Contributor

farindk commented Jan 28, 2023

I have added a couple more fixes for crashes that were reported today.
I propose to release v1.0.11 including these.

@fancycode Let me know when you are ready to compile the Debian packages. Then I'll tag v1.0.11.

@coldtobi FYI

@coldtobi
Copy link

coldtobi commented Feb 1, 2023

@fancycode any updates? (I'd do another NMU update with the new version + possible patches sine 1.10.0 otherwise, possibly this Saturday, as this will be required to fix the CVEs in bullseye.)

@farindk (FYI)

farindk added a commit that referenced this issue Feb 1, 2023
@farindk
Copy link
Contributor

farindk commented Feb 1, 2023

I have released v1.0.11.

@fancycode
Copy link
Member

@coldtobi I'm trying to finish packaging for 1.0.11 today

@fancycode
Copy link
Member

New packaging is uploaded to mentors (https://mentors.debian.net/package/libde265/) and waiting for being accepted.

@fancycode
Copy link
Member

I think this can be closed now, @farindk what do you think?

@farindk
Copy link
Contributor

farindk commented Feb 2, 2023

@fancycode Thank you for building the package.

@farindk farindk closed this as completed Feb 2, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants