lib*-perl dependencies of dh-golang and libtype-tiny-perl

Bug #1493037 reported by Matthias Klose
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Ubuntu
Fix Released
Undecided
Unassigned

Bug Description

lib*-perl dependencies of dh-golang and libtype-tiny-perl, which need a MIR

 - every package is maintained by the Debian Perl Group.
 - subscribed Ubuntu Foundations Bugs to all these packages.

libany-moose-perl
libclass-forward-perl
libclass-insideout-perl
libclass-isa-perl
libconfig-any-perl
libconfig-file-perl
libcrypt-blowfish-perl
libcrypt-cast5-perl
libcrypt-cbc-perl
libcrypt-des-ede3-perl
libcrypt-des-perl
libcrypt-rijndael-perl
libdata-dump-perl
libdata-perl-perl
libdata-serializer-perl
libdevel-findref-perl
libdevel-leak-perl
libfile-pushd-perl
libhash-flatten-perl
libhash-merge-perl
libio-captureoutput-perl
liblog-trace-perl
libmatch-simple-perl
libmatch-simple-xs-perl
libmodule-find-perl
libmodule-install-authortests-perl
libmodule-install-extratests-perl
libmodule-install-perl
libmodule-scandeps-perl
libmoosex-configfromfile-perl
libmoosex-getopt-perl
libmoosex-role-parameterized-perl
libmoosex-role-withoverloading-perl
libmoosex-simpleconfig-perl
libmoosex-types-common-perl
libmoosex-types-path-class-perl
libmoosex-types-path-tiny-perl
libmoosex-types-perl
libmoosex-types-stringlike-perl
libmoox-handlesvia-perl
libmousex-types-perl
libobject-accessor-perl
libphp-serialization-perl
libprefork-perl
libscalar-list-utils-perl
libsub-infix-perl
libtest-assertions-perl
libtest-checkdeps-perl
libtest-refcount-perl
libtest-simple-perl
libtest-trap-perl
libtype-tiny-xs-perl
libvalidation-class-perl
libxml-dumper-perl
libyaml-syck-perl

Tags: bot-comment

CVE References

Revision history for this message
Ubuntu Foundations Team Bug Bot (crichton) wrote :

Thank you for taking the time to report this bug and helping to make Ubuntu better. It seems that your bug report is not filed about a specific source package though, rather it is just filed against Ubuntu in general. It is important that bug reports be filed about source packages so that people interested in the package can find the bugs about it. You can find some hints about determining what package your bug might be about at https://wiki.ubuntu.com/Bugs/FindRightPackage. You might also ask for help in the #ubuntu-bugs irc channel on Freenode.

To change the source package that this bug is filed about visit https://bugs.launchpad.net/ubuntu/+bug/1493037/+editstatus and add the package name in the text box next to the word Package.

[This is an automated message. I apologize if it reached you inappropriately; please just reply to this message indicating so.]

tags: added: bot-comment
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

doko asked me to give these a quick look. There are no open CVEs in any of them and only libcrypt-cbc-perl has a CVE history: CVE-2006-0898 (fixed via debian sync prior to dapper release). I reviewed the changes for the fix and they were easy to understand. As for the libcrypt-* packages listed here, they all have testsuites and look to be supportable. Nothing here needs further security review.

Michael Terry (mterry)
Changed in ubuntu:
assignee: nobody → Michael Terry (mterry)
Revision history for this message
Michael Terry (mterry) wrote :

Since this is such a large amount of packages, I'm tempted to do a bulk review. And since perl packages tend to be well maintained in Debian with good packaging, I'll allow myself to do that.

- All these packages are in sync
- I've looked over all their packaging, and it is mostly modern and simple, with few patches
- Any that have standard perl-tests have them run as part of the build. Most have tests, but I didn't verify the exact count.
- They all build in a current wily amd64 pbuilder
- They are all looked after by the Perl Group in Debian and the Foundations group in Ubuntu
- A couple are deprecated modules, but no biggie. If an upstream source uses them, it's not worth forcing them to switch right now.
- There are quite a few encryption related modules, but Jamie gave the OK.

So, I'm approving this whole slate of perl modules.

Changed in ubuntu:
status: New → Fix Committed
Revision history for this message
Matthias Klose (doko) wrote :

all promoted

Changed in ubuntu:
assignee: Michael Terry (mterry) → nobody
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.