FOSS Activites in January 2022

Here’s my (twenty-eighth) monthly but brief update about the activities I’ve done in the F/L/OSS world.

Debian

This was my 37th month of actively contributing to Debian. I became a DM in late March 2019 and a DD on Christmas ‘19! \o/

Just churning through the backlog again this month. Ugh.

Anyway, I did the following stuff in Debian:

Uploads and bug fixes:

  • ruby2.5 (2.5.5-3+deb10u4) - Fixing CVE-2021-28965, CVE-2021-31799, CVE-2021-31810, CVE-2021-32066, Fixes: CVE-2021-41817, and CVE-2021-41819 for Buster.
  • mat2 (0.12.2-1.1) - Add patch to fix AssertionError in test_libmat2, fixing bug #1002418.
  • ruby-fast-gettext (2.0.3-2) - Add patch to fix FTBFS, fixing bug #1002103.
  • python-flask-marshmallow (0.14.0-1) - New upstream version, v0.14.0, fixing bug #989269.
  • ruby-rack (2.2.3-4) - Add patch to fix build and autopkgtest.
  • ruby2.7 (2.7.4-1+deb11u1) - Fixing CVE-2021-41816, CVE-2021-41817, and CVE-2021-41819 for Bullseye.

Other $things:

  • Mentoring for newcomers.
  • Moderation of -project mailing list.

Ubuntu

This was my 12th month of actively contributing to Ubuntu. Now that I joined Canonical to work on Ubuntu full-time, there’s a bunch of things I do! \o/

I mostly worked on different things, I guess.

I was too lazy to maintain a list of things I worked on so there’s no concrete list atm. Maybe I’ll get back to this section later or will start to list stuff from the fall, as I was doing before. :D


Debian (E)LTS

Debian Long Term Support (LTS) is a project to extend the lifetime of all Debian stable releases to (at least) 5 years. Debian LTS is not handled by the Debian security team, but by a separate group of volunteers and companies interested in making it a success.

And Debian Extended LTS (ELTS) is its sister project, extending support to the Jessie release (+2 years after LTS support).

This was my twenty-seventh month as a Debian LTS and eighteenth month as a Debian ELTS paid contributor.
I was assigned 58.25 hours for LTS and 60.00 hours for ELTS and worked on the following things:
(I already worked for 20h in the last month (December) because of vacation :D)

LTS CVE Fixes and Announcements:

ELTS CVE Fixes and Announcements:

Other (E)LTS Work:

  • Front-desk duty from 24-01 to 30-01 for both LTS and ELTS.
  • Triaged wordpress, php-nette, samba, wordpress, and qtsvg-opensource-src, qt4-x11, python2.7, python3.4, libspring-java, librecad, minetest, spip, varnish, libimage-exiftool-perl, libsixel, openexr, openssl, phpmyadmin, util-linux, shadow, ruby2.5, and ruby2.7.
  • Mark CVE-2022-21648/php-nette as not-affected for stretch and jessie.
  • Mark CVE-2021-23803/php-nette as not-affected for stretch and jessie.
  • Mark CVE-2021-22060/libspring-java as end-of-life for stretch.
  • Mark CVE-2022-23935/libimage-exiftool-perl as no-dsa for stretch.
  • Mark CVE-2021-45340/libsixel as no-dsa for stretch.
  • Mark CVE-2021-45942/openexr as no-dsa for stretch.
  • Mark CVE-2021-4160/openssl as no-dsa for stretch.
  • Mark CVE-2022-23807/phpmyadmin as not-affected at all.
  • Mark CVE-2022-23808/phpmyadmin as not-affected at all.
  • Mark CVE-2022-23935/libimage-exiftool-perl as no-dsa for jessie.
  • Mark CVE-2021-4160/openssl as no-dsa for jessie.
  • Mark CVE-2021-3995/util-linux as not-affected for jessie.
  • Mark CVE-2021-3996/util-linux as not-affected for jessie.
  • Mark CVE-2022-23959/varnish as not-affected for jessie.
  • Mark CVE-2021-4160/openssl as ignored instead for stretch.
  • Auto EOL’ed 389-ds-base, mongodb, kfreebsd-10, spip, strongswan, libsixel, xen, connman, minetest, and linux for jessie.
  • Attended monthly Debian LTS meeting.
  • Answered questions (& discussions) on IRC (#debian-lts and #debian-elts).
  • General and other discussions on LTS private and public mailing list.

Debian LTS Survey

I’ve spent 5 hours on the LTS survey on the following bits:
(however, I’ll invoice them together next month)

  • Went through the content to put in the survey.
  • Put some of them there according to the question type.
  • Been going back and forth updating the status of the survey on the issue.

Until next time.
:wq for today.