public inbox for cygwin@cygwin.com
 help / color / mirror / Atom feed
* Mercurial update needed for security fixes
@ 2017-08-17  9:49 Andy Moreton
  2017-09-18 15:27 ` Andy Moreton
  0 siblings, 1 reply; 6+ messages in thread
From: Andy Moreton @ 2017-08-17  9:49 UTC (permalink / raw)
  To: cygwin

Hi,

Can the mercurial maintainer please update to upstream Hg 4.3.1, to get
the fixes for CVE-2017-1000115 and CVE-2017-1000116.

Thanks,

    AndyM


--
Problem reports:       http://cygwin.com/problems.html
FAQ:                   http://cygwin.com/faq/
Documentation:         http://cygwin.com/docs.html
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: Mercurial update needed for security fixes
  2017-08-17  9:49 Mercurial update needed for security fixes Andy Moreton
@ 2017-09-18 15:27 ` Andy Moreton
  2017-09-18 16:58   ` Ken Brown
  0 siblings, 1 reply; 6+ messages in thread
From: Andy Moreton @ 2017-09-18 15:27 UTC (permalink / raw)
  To: cygwin

On Thu 17 Aug 2017, Andy Moreton wrote:

Ping?

> Hi,
>
> Can the mercurial maintainer please update to upstream Hg 4.3.1, to get
> the fixes for CVE-2017-1000115 and CVE-2017-1000116.
>
> Thanks,
>
>     AndyM


--
Problem reports:       http://cygwin.com/problems.html
FAQ:                   http://cygwin.com/faq/
Documentation:         http://cygwin.com/docs.html
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: Mercurial update needed for security fixes
  2017-09-18 15:27 ` Andy Moreton
@ 2017-09-18 16:58   ` Ken Brown
  2017-09-25 17:31     ` Andy Moreton
  2017-09-26 13:24     ` Mercurial update needed for security fixes (fixed in 4.3.2-1) Jari Aalto
  0 siblings, 2 replies; 6+ messages in thread
From: Ken Brown @ 2017-09-18 16:58 UTC (permalink / raw)
  To: cygwin; +Cc: Jari Aalto

On 9/18/2017 11:27 AM, Andy Moreton wrote:
> On Thu 17 Aug 2017, Andy Moreton wrote:
> 
> Ping?
> 
>> Hi,
>>
>> Can the mercurial maintainer please update to upstream Hg 4.3.1, to get
>> the fixes for CVE-2017-1000115 and CVE-2017-1000116.

I don't know if he reads the list.  I'm adding him to the Cc.

Ken


--
Problem reports:       http://cygwin.com/problems.html
FAQ:                   http://cygwin.com/faq/
Documentation:         http://cygwin.com/docs.html
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: Mercurial update needed for security fixes
  2017-09-18 16:58   ` Ken Brown
@ 2017-09-25 17:31     ` Andy Moreton
  2017-09-25 17:35       ` Vince Rice
  2017-09-26 13:24     ` Mercurial update needed for security fixes (fixed in 4.3.2-1) Jari Aalto
  1 sibling, 1 reply; 6+ messages in thread
From: Andy Moreton @ 2017-09-25 17:31 UTC (permalink / raw)
  To: cygwin

On Mon 18 Sep 2017, Ken Brown wrote:

> On 9/18/2017 11:27 AM, Andy Moreton wrote:
>> On Thu 17 Aug 2017, Andy Moreton wrote:
>>
>> Ping?
>>
>>> Hi,
>>>
>>> Can the mercurial maintainer please update to upstream Hg 4.3.1, to get
>>> the fixes for CVE-2017-1000115 and CVE-2017-1000116.
>
> I don't know if he reads the list.  I'm adding him to the Cc.
>
> Ken

Still no response. If the maintiner does not read the project list or
respond to email, then all of his packages are effectively abandoned.

Can we please have a *security update* for mercurial ?

    AndyM


--
Problem reports:       http://cygwin.com/problems.html
FAQ:                   http://cygwin.com/faq/
Documentation:         http://cygwin.com/docs.html
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: Mercurial update needed for security fixes
  2017-09-25 17:31     ` Andy Moreton
@ 2017-09-25 17:35       ` Vince Rice
  0 siblings, 0 replies; 6+ messages in thread
From: Vince Rice @ 2017-09-25 17:35 UTC (permalink / raw)
  To: The Cygwin Mailing List

> On Sep 25, 2017, at 12:31 PM, Andy Moreton <andrewjmoreton@gmail.com> wrote:
> 
> On Mon 18 Sep 2017, Ken Brown wrote:
> 
>> On 9/18/2017 11:27 AM, Andy Moreton wrote:
>>> On Thu 17 Aug 2017, Andy Moreton wrote:
>>> 
>>> Ping?
>>> 
>>>> Hi,
>>>> 
>>>> Can the mercurial maintainer please update to upstream Hg 4.3.1, to get
>>>> the fixes for CVE-2017-1000115 and CVE-2017-1000116.
>> 
>> I don't know if he reads the list.  I'm adding him to the Cc.
>> 
>> Ken
> 
> Still no response. If the maintiner does not read the project list or
> respond to email, then all of his packages are effectively abandoned.
> 
> Can we please have a *security update* for mercurial ?

And if "effectively abandoned," then there's no one to update them. Are you volunteering?
--
Problem reports:       http://cygwin.com/problems.html
FAQ:                   http://cygwin.com/faq/
Documentation:         http://cygwin.com/docs.html
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: Mercurial update needed for security fixes (fixed in 4.3.2-1)
  2017-09-18 16:58   ` Ken Brown
  2017-09-25 17:31     ` Andy Moreton
@ 2017-09-26 13:24     ` Jari Aalto
  1 sibling, 0 replies; 6+ messages in thread
From: Jari Aalto @ 2017-09-26 13:24 UTC (permalink / raw)
  To: Ken Brown; +Cc: cygwin

On 2017-09-18 12:58, Ken Brown wrote:
| > > 
| > > Can the mercurial maintainer please update to upstream Hg 4.3.1, to get
| > > the fixes for CVE-2017-1000115 and CVE-2017-1000116.
| 
| I don't know if he reads the list.  I'm adding him to the Cc.

Thanks, new release uploaded,
Jari

--
Problem reports:       http://cygwin.com/problems.html
FAQ:                   http://cygwin.com/faq/
Documentation:         http://cygwin.com/docs.html
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2017-09-26 13:24 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2017-08-17  9:49 Mercurial update needed for security fixes Andy Moreton
2017-09-18 15:27 ` Andy Moreton
2017-09-18 16:58   ` Ken Brown
2017-09-25 17:31     ` Andy Moreton
2017-09-25 17:35       ` Vince Rice
2017-09-26 13:24     ` Mercurial update needed for security fixes (fixed in 4.3.2-1) Jari Aalto

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).