-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Wed, 03 Feb 2021 16:41:01 +0530 Source: open-build-service Binary: obs-server obs-worker obs-api obs-productconverter obs-utils Architecture: source all Version: 2.7.1-10+deb9u1 Distribution: stretch-security Urgency: high Maintainer: Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@lists.alioth.debian.org> Changed-By: Utkarsh Gupta <utkarsh@debian.org> Description: obs-api - Open Build Service (api) obs-productconverter - Open Build Service (product definition utility) obs-server - Open Build Service (server component) obs-utils - Open Build Service (utilities) obs-worker - Open Build Service (build host component) Changes: open-build-service (2.7.1-10+deb9u1) stretch-security; urgency=high . * Non-maintainer upload by the LTS team. * Use Redcarpet Safe render to base OBS markdown render. (Fixes: CVE-2020-8020) * bs_srcserver: Forbid the creation of a _link in mergeservicerun. (Fixes: CVE-2020-2081) Checksums-Sha1: 16cd5e9b326bd3156fa70114e17452fc5e9290ea 3363 open-build-service_2.7.1-10+deb9u1.dsc 5a101f781c11d4058f98a2cb1ce7d14bc8dbf18b 1960826 open-build-service_2.7.1.orig.tar.gz f032b9af10ab584320be6d7635ee5755cbc5706b 203556 open-build-service_2.7.1-10+deb9u1.debian.tar.xz d0caebaa2ea60ff52db7fc66b708f74eff8c7858 1341444 obs-api_2.7.1-10+deb9u1_all.deb 926990b6fec67be2feeaacea9f323f8e69a4468b 21164 obs-productconverter_2.7.1-10+deb9u1_all.deb 5baf7c1f10524fad902ec4d30f14e80ef712272d 326364 obs-server_2.7.1-10+deb9u1_all.deb 18221bffbb345e53607bdedfdea1b6578c748fb4 7062 obs-utils_2.7.1-10+deb9u1_all.deb c4b714c50863a4cd4d4ebef733d007614e98e8e3 12272 obs-worker_2.7.1-10+deb9u1_all.deb 00ca0ee48640003f887012a9f4f8defe4c59a559 13500 open-build-service_2.7.1-10+deb9u1_amd64.buildinfo Checksums-Sha256: 5f72e9f0ef394e218108a1149870e3894a879bbb3eb713c7bf7dd9d14de19fb3 3363 open-build-service_2.7.1-10+deb9u1.dsc 2e0af09be88e536a21039bf7aedf43396e41d0dbe2d595295f321fa7d293c757 1960826 open-build-service_2.7.1.orig.tar.gz bbf20ed75a146cfe67e49d08841bfeb5d18b729d14153d659973080b65f26e73 203556 open-build-service_2.7.1-10+deb9u1.debian.tar.xz 5aaa77a9c5f11c1fec783b9d1b1f7df664bf90ce06802d5bebefff72d12f190d 1341444 obs-api_2.7.1-10+deb9u1_all.deb f46dfc3856cfacba2b88bea5be3df3dc5e2001d3da0f74e344221656a1926fd8 21164 obs-productconverter_2.7.1-10+deb9u1_all.deb 6e37cc236c976909a68210cfb35bb9e4cb2154812b9a0f0831852dea464d8b04 326364 obs-server_2.7.1-10+deb9u1_all.deb d5be91fe8ee4c714b8c40d25f5cc5909fb10dd8317450fed85eb58feb9c9f6e9 7062 obs-utils_2.7.1-10+deb9u1_all.deb 3530d7ad5dbc41681b683ee6d6930aadd58758d17b042013287f48c5734e7c22 12272 obs-worker_2.7.1-10+deb9u1_all.deb 5fbcb4e116feac690b0aef2f8d3aeeb0ec0f50e6d2369d1d57daed2ad92c7d9f 13500 open-build-service_2.7.1-10+deb9u1_amd64.buildinfo Files: d58f39fb1be612a71f699326af2927b8 3363 devel optional open-build-service_2.7.1-10+deb9u1.dsc 9bde2a4583880ae1a4387c078fcd188d 1960826 devel optional open-build-service_2.7.1.orig.tar.gz 9ebb92ed6546b135962c9c89d1cd98f3 203556 devel optional open-build-service_2.7.1-10+deb9u1.debian.tar.xz 7bc7743d9c860f3122ca0a2799f0176a 1341444 devel optional obs-api_2.7.1-10+deb9u1_all.deb 5ad1fd53eeb0acdf18735d94248d0671 21164 devel optional obs-productconverter_2.7.1-10+deb9u1_all.deb a9eb031b1dbbae7e7280a0fe8919c0e6 326364 devel optional obs-server_2.7.1-10+deb9u1_all.deb b2f7b7403edd3afc3013ecbf3df6eb6f 7062 devel optional obs-utils_2.7.1-10+deb9u1_all.deb a1eb027b94a0c11d357ab3539c470aaa 12272 devel optional obs-worker_2.7.1-10+deb9u1_all.deb 323c7fb51c80636c8b5e6373fa78b082 13500 devel optional open-build-service_2.7.1-10+deb9u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQJHBAEBCAAxFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAmAahhwTHHV0a2Fyc2hA ZGViaWFuLm9yZwAKCRCCPpZ2BsNLlmytEACUWpRVUUehQ5K7AKTijFai1c5uEEP2 knc7l4BrWMHAaV4YOd8OzItb2cYsR7fdqU7sXmhhSy2WFkyTtH0SubL31Ff+R1Ii 8s4BrcaksfS/cmYVIxPJ9W2cY0ujGV0EQSwaXod+Hk/u+VZdTzq6fRdATz/NgAKz kxmEDzvNbeXtIBiqhfc9bkrkgyw0oQl9ZO0wOW0dnqCCeOmXT65mESA1Aq4Musad H2cXsrC0Z3UDKYg58fWm7UC1CpS9J55hgAbNngucCe4NOy/y29LOXGNKnWEu6Of+ +Xa5crKJEE4D9z6dXGvY4dWBQXC4hZVNQU95P54o0BETbKOb/HZrFsmmX9NPk9UY PDfEGAxztNS3FNqWM7CUlw62lEyT2cZbzLFuUZAeuOq+pBksmINrZqy5molBpqQn V7TXE5cNamMetHD3gHhFL8w1jhaZHYbgHZvEBkDVJ+mfp2nE3q4H+MMXxVCtp0rx vym3knW9Q3XWU9c1nf6g6/560/pe3VikMnVjXb0KPv6VR7LE1t8oNkV16wyJDbrM DGOjd6N+AurW16vP5gy4TT/Ae+b4BESedYI7q9PD2jx0ER38CbYk7YD3M4vB3CpQ 1Lxb/bfGwiuEJiwZXdY6c0r25X8wurHoP8Iax5F+C5hbjxvvRKsLDafI8zee8/9j II899cuZlNc++g== =IsvP -----END PGP SIGNATURE-----