Debian Package Tracker
Register | Log in
Subscribe

open-build-service

Choose email to subscribe with

general
  • source: open-build-service (main)
  • version: 2.9.4-3
  • maintainer: Debian Ruby Extras Maintainers (archive) (DMD)
  • uploaders: Andrew Lee (李健秋) [DMD] – Lucas Kanashiro [DMD] – Héctor Orón Martínez [DMD]
  • arch: all
  • std-ver: 4.3.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 2.7.1-10
  • unstable: 2.9.4-3
versioned links
  • 2.7.1-10: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.9.4-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • obs-api (4 bugs: 0, 3, 1, 0)
  • obs-productconverter
  • obs-server (1 bugs: 1, 0, 0, 0)
  • obs-utils
  • obs-worker
action needed
A new upstream version is available: 2.10.7 high
A new upstream version 2.10.7 is available, you should consider packaging it.
Created: 2020-06-29 Last update: 2021-01-16 14:02
9 security issues in stretch high
There are 9 open security issues in stretch.
2 important issues:
  • CVE-2020-8020: A Improper Neutralization of Input During Web Page Generation vulnerability in open-build-service allows remote attackers to store arbitrary JS code to cause XSS. This issue affects: openSUSE open-build-service versions prior to 7cc32c8e2ff7290698e101d9a80a9dc29a5500fb.
  • CVE-2020-8021: a Improper Access Control vulnerability in of Open Build Service allows remote attackers to read files of an OBS package where the sourceaccess/access is disabled This issue affects: Open Build Service versions prior to 2.10.5.
7 issues skipped by the security teams:
  • CVE-2017-5188: The bs_worker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside of the package source directory during build, allowing leakage of private information.
  • CVE-2017-9268: In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users to cause operations on projects where they did not have permissions leading to denial of service (resource consumption).
  • CVE-2018-12466: openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links.
  • CVE-2018-12467: Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDevelPackage attribute, a similar issue to CVE-2018-7689.
  • CVE-2018-12479: A Improper Input Validation vulnerability in Open Build Service allows remote attackers to cause DoS by specifying crafted request IDs. Affected releases are openSUSE Open Build Service: versions prior to 01b015ca2a320afc4fae823465d1e72da8bd60df.
  • CVE-2018-7688: A missing permission check in the review handling of openSUSE Open Build Service before 2.9.3 allowed all authenticated users to modify sources in projects where they do not have write permissions.
  • CVE-2018-7689: Lack of permission checks in the InitializeDevelPackage function in openSUSE Open Build Service before 2.9.3 allowed authenticated users to modify packages where they do not have write permissions.
Please fix them.
Created: 2018-03-05 Last update: 2020-09-09 10:07
4 security issues in sid high
There are 4 open security issues in sid.
4 important issues:
  • CVE-2017-9268: In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users to cause operations on projects where they did not have permissions leading to denial of service (resource consumption).
  • CVE-2018-12466: openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links.
  • CVE-2020-8020: A Improper Neutralization of Input During Web Page Generation vulnerability in open-build-service allows remote attackers to store arbitrary JS code to cause XSS. This issue affects: openSUSE open-build-service versions prior to 7cc32c8e2ff7290698e101d9a80a9dc29a5500fb.
  • CVE-2020-8021: a Improper Access Control vulnerability in of Open Build Service allows remote attackers to read files of an OBS package where the sourceaccess/access is disabled This issue affects: Open Build Service versions prior to 2.10.5.
Please fix them.
Created: 2018-03-05 Last update: 2020-09-09 10:07
Depends on packages which need a new maintainer normal
The packages that open-build-service depends on which need a new maintainer are:
  • rpm (#923352)
    • Depends: rpm
Created: 2019-11-22 Last update: 2021-01-16 13:06
The package has not entered testing even though the delay is over normal
The package has not entered testing even though the 5-day delay is over. Check why.
Created: 2020-04-19 Last update: 2021-01-16 13:04
Multiarch hinter reports 1 issue(s) normal
There are issues with the multiarch metadata for this package.
  • obs-productconverter could be marked Multi-Arch: foreign
Created: 2016-12-16 Last update: 2021-01-16 10:37
piuparts found (un)installation error(s) normal
Piuparts stresses package installation, uninstallation, upgrade, ... While doing such tests, one or more errors were found for the following suites:
  • sid - piuparts
You should fix them.
Created: 2021-01-15 Last update: 2021-01-15 18:30
version in VCS is newer than in repository, is it time to upload? normal
vcswatch reports that this package seems to have a new changelog entry (version 2.9.4-4, distribution UNRELEASED) and new commits in its VCS. You should consider whether it's time to make an upload.

Here are the relevant commit messages:
commit f4bc540ee9171d168f532ee1bf1d2c289d0228ee
Author: Debian Janitor <janitor@jelmer.uk>
Date:   Mon Apr 13 21:53:18 2020 +0000

    Update standards version to 4.4.1, no changes needed.
    
    Fixes: lintian: out-of-date-standards-version
    See-also: https://lintian.debian.org/tags/out-of-date-standards-version.html

commit c2996acbceea5270046304135c65b5a3a3c53760
Author: Debian Janitor <janitor@jelmer.uk>
Date:   Mon Apr 13 21:52:47 2020 +0000

    Drop unnecessary dh arguments: --parallel
    
    Fixes: lintian: debian-rules-uses-unnecessary-dh-argument
    See-also: https://lintian.debian.org/tags/debian-rules-uses-unnecessary-dh-argument.html

commit 54737fdffca17d4b828c87725a593b4e5cf83fdd
Author: Debian Janitor <janitor@jelmer.uk>
Date:   Mon Apr 13 21:52:15 2020 +0000

    Set upstream metadata fields: Bug-Database, Bug-Submit, Repository, Repository-Browse.
    
    Fixes: lintian: upstream-metadata-file-is-missing
    See-also: https://lintian.debian.org/tags/upstream-metadata-file-is-missing.html
    
    
    Fixes: lintian: upstream-metadata-missing-bug-tracking
    See-also: https://lintian.debian.org/tags/upstream-metadata-missing-bug-tracking.html
    
    
    Fixes: lintian: upstream-metadata-missing-repository
    See-also: https://lintian.debian.org/tags/upstream-metadata-missing-repository.html

commit 6fe236617c63d6af772e8d1ced869d43883aa2a7
Author: Debian Janitor <janitor@jelmer.uk>
Date:   Mon Apr 13 21:51:37 2020 +0000

    Set debhelper-compat version in Build-Depends.
    
    Fixes: lintian: uses-debhelper-compat-file
    See-also: https://lintian.debian.org/tags/uses-debhelper-compat-file.html

commit 3e6ae98a7ccb8ca9baa3e7a537ebc028530c3a83
Author: Debian Janitor <janitor@jelmer.uk>
Date:   Mon Apr 13 21:51:06 2020 +0000

    Bump debhelper from old 9 to 12.
    + Use dh_installsystemd rather than deprecated dh_systemd_enable.
    + Use dh_installsystemd rather than deprecated dh_systemd_start.
    
    Fixes: lintian: package-uses-old-debhelper-compat-version
    See-also: https://lintian.debian.org/tags/package-uses-old-debhelper-compat-version.html

commit 27a7619ce7f9b3fa160d59e4683a5375503d7dc0
Author: Debian Janitor <janitor@jelmer.uk>
Date:   Mon Apr 13 21:50:33 2020 +0000

    Wrap long lines in changelog entries: 2.9.4-3.
    
    Fixes: lintian: debian-changelog-line-too-long
    See-also: https://lintian.debian.org/tags/debian-changelog-line-too-long.html

commit e9c8a282baafb517bba95796a1e7300ff2866c36
Author: Debian Janitor <janitor@jelmer.uk>
Date:   Mon Apr 13 21:50:02 2020 +0000

    debian/copyright: use spaces rather than tabs to start continuation lines.
    
    Fixes: lintian: tab-in-license-text
    See-also: https://lintian.debian.org/tags/tab-in-license-text.html

commit 849bf2e679215755733d129849ef48b2476607cc
Author: Debian Janitor <janitor@jelmer.uk>
Date:   Mon Apr 13 21:49:30 2020 +0000

    Use secure copyright file specification URI.
    
    Fixes: lintian: insecure-copyright-format-uri
    See-also: https://lintian.debian.org/tags/insecure-copyright-format-uri.html
Created: 2020-04-14 Last update: 2021-01-15 13:04
lintian reports 38 warnings normal
Lintian reports 38 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2020-07-29 Last update: 2020-09-21 06:03
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.5.1 instead of 4.3.0).
Created: 2019-07-08 Last update: 2020-11-17 05:41
testing migrations
  • excuses:
    • Migrates after: ruby-codemirror-rails
    • Migration status for open-build-service (- to 2.9.4-3): BLOCKED: Rejected/violates migration policy/introduces a regression
    • Issues preventing migration:
    • Updating open-build-service introduces new bugs: #924233
    • Rejected due to piuparts regression - https://piuparts.debian.org/sid/source/o/open-build-service.html
    • autopkgtest for open-build-service/2.9.4-3: amd64: No test results, arm64: No test results, armhf: Regression ♻ , i386: Regression ♻ , ppc64el: Regression ♻
    • Build-Depends(-Arch): open-build-service ruby-codemirror-rails
    • Depends: open-build-service ruby-codemirror-rails
    • Additional info:
    • 277 days old (needed 5 days)
    • Not considered
news
[rss feed]
  • [2020-04-13] Accepted open-build-service 2.9.4-3 (source) into unstable (Lucas Kanashiro)
  • [2019-03-18] Accepted open-build-service 2.9.4-2 (source) into unstable (Lucas Kanashiro)
  • [2019-02-07] Accepted open-build-service 2.9.4-1 (source all) into unstable (Andrew Lee (李健秋)) (signed by: 李健秋 Andrew Lee)
  • [2018-10-09] Accepted open-build-service 2.7.4-3 (source) into unstable (Andrew Lee (李健秋)) (signed by: 李健秋 Andrew Lee)
  • [2018-04-26] open-build-service REMOVED from testing (Debian testing watch)
  • [2018-03-17] open-build-service 2.7.4-2 MIGRATED to testing (Debian testing watch)
  • [2018-03-10] open-build-service REMOVED from testing (Debian testing watch)
  • [2017-09-04] open-build-service 2.7.4-2 MIGRATED to testing (Debian testing watch)
  • [2017-09-03] open-build-service REMOVED from testing (Debian testing watch)
  • [2017-08-12] open-build-service 2.7.4-2 MIGRATED to testing (Debian testing watch)
  • [2017-08-06] Accepted open-build-service 2.7.4-2 (source) into unstable (Andrew Lee (李健秋)) (signed by: 李健秋 Andrew Lee)
  • [2017-08-06] Accepted open-build-service 2.8.2-1 (source) into experimental (Andrew Lee (李健秋)) (signed by: 李健秋 Andrew Lee)
  • [2017-08-03] Accepted open-build-service 2.7.4-1 (source) into unstable (Andrew Lee (李健秋)) (signed by: 李健秋 Andrew Lee)
  • [2017-02-05] open-build-service 2.7.1-10 MIGRATED to testing (Debian testing watch)
  • [2017-01-25] Accepted open-build-service 2.7.1-10 (source all) into unstable (Andrew Lee (李健秋)) (signed by: 李健秋 Andrew Lee)
  • [2017-01-02] open-build-service 2.7.1-9 MIGRATED to testing (Debian testing watch)
  • [2016-12-22] Accepted open-build-service 2.7.1-9 (source) into unstable (Andrew Lee (李健秋)) (signed by: 李健秋 Andrew Lee)
  • [2016-12-19] Accepted open-build-service 2.7.1-8 (source amd64) into unstable (Andrew Lee (李健秋)) (signed by: 李健秋 Andrew Lee)
  • [2016-12-15] Accepted open-build-service 2.7.1-7 (source amd64) into unstable (Andrew Lee (李健秋)) (signed by: 李健秋 Andrew Lee)
  • [2016-12-08] Accepted open-build-service 2.7.1-6 (source amd64) into experimental (Andrew Lee (李健秋)) (signed by: 李健秋 Andrew Lee)
  • [2016-11-17] Accepted open-build-service 2.7.1-5 (source amd64) into experimental (Andrew Lee (李健秋)) (signed by: 李健秋 Andrew Lee)
  • [2016-10-25] Accepted open-build-service 2.7.1-4 (source amd64) into experimental (Andrew Lee (李健秋)) (signed by: 李健秋 Andrew Lee)
  • [2016-10-20] Accepted open-build-service 2.7.1-3 (source amd64) into experimental (Andrew Lee (李健秋)) (signed by: 李健秋 Andrew Lee)
  • [2016-10-19] Accepted open-build-service 2.7.1-2 (source amd64) into experimental (Andrew Lee (李健秋)) (signed by: 李健秋 Andrew Lee)
  • [2016-09-20] Accepted open-build-service 2.7.1-1 (source amd64) into experimental, experimental (Andrew Lee (李健秋)) (signed by: 李健秋 Andrew Lee)
bugs [bug history graph]
  • all: 9
  • RC: 1
  • I&N: 5
  • M&W: 2
  • F&P: 1
  • patch: 0
links
  • homepage
  • lintian (0, 38)
  • buildd: logs, clang
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debci

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing