From noreply at release.debian.org Sun Feb 1 04:39:10 2026 From: noreply at release.debian.org (Debian testing autoremoval watch) Date: Sun, 01 Feb 2026 04:39:10 +0000 Subject: [Pkg-javascript-devel] node-import-meta-resolve is marked for autoremoval from testing Message-ID: node-import-meta-resolve 4.1.0-1 is marked for autoremoval from testing on 2026-02-21 It is affected by these RC bugs: 1126218: node-import-meta-resolve: FTBFS: lib/resolve.js(69,3): error TS2578: Unused '@ts-expect-error' directive. https://bugs.debian.org/1126218 For more information on the autoremoval process, including hints to prevent autoremoval can be found on the wiki: https://wiki.debian.org/Autoremoval This mail is generated by: https://salsa.debian.org/release-team/release-tools/-/blob/master/mailer/mail_autoremovals.pl Autoremoval data is generated by: https://salsa.debian.org/qa/udd/-/blob/master/udd/testing_autoremovals_gatherer.pl From noreply at release.debian.org Sun Feb 1 04:39:10 2026 From: noreply at release.debian.org (Debian testing watch) Date: Sun, 01 Feb 2026 04:39:10 +0000 Subject: [Pkg-javascript-devel] libjs-graphael 0.5+dfsg-2 MIGRATED to testing Message-ID: FYI: The status of the libjs-graphael source package in Debian's testing distribution has changed. Previous version: 0.5+dfsg-1.1 Current version: 0.5+dfsg-2 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a day you will receive later changes on the next day. See https://release.debian.org/testing-watch/ for more information. From noreply at release.debian.org Sun Feb 1 04:39:11 2026 From: noreply at release.debian.org (Debian testing watch) Date: Sun, 01 Feb 2026 04:39:11 +0000 Subject: [Pkg-javascript-devel] node-js-sdsl 4.1.4-3 MIGRATED to testing Message-ID: FYI: The status of the node-js-sdsl source package in Debian's testing distribution has changed. Previous version: (not in testing) Current version: 4.1.4-3 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a day you will receive later changes on the next day. See https://release.debian.org/testing-watch/ for more information. From noreply at release.debian.org Sun Feb 1 04:39:11 2026 From: noreply at release.debian.org (Debian testing watch) Date: Sun, 01 Feb 2026 04:39:11 +0000 Subject: [Pkg-javascript-devel] node-number-allocator 1.0.14-1 MIGRATED to testing Message-ID: FYI: The status of the node-number-allocator source package in Debian's testing distribution has changed. Previous version: (not in testing) Current version: 1.0.14-1 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a day you will receive later changes on the next day. See https://release.debian.org/testing-watch/ for more information. From noreply at release.debian.org Sun Feb 1 04:39:26 2026 From: noreply at release.debian.org (Debian testing autoremoval watch) Date: Sun, 01 Feb 2026 04:39:26 +0000 Subject: [Pkg-javascript-devel] node-carto is marked for autoremoval from testing Message-ID: node-carto 1.2.0-5 is marked for autoremoval from testing on 2026-03-01 It (build-)depends on packages with these RC bugs: 1125242: aflplusplus: build-depends on gcc-multilib [s390x], which will get removed https://bugs.debian.org/1125242 For more information on the autoremoval process, including hints to prevent autoremoval can be found on the wiki: https://wiki.debian.org/Autoremoval This mail is generated by: https://salsa.debian.org/release-team/release-tools/-/blob/master/mailer/mail_autoremovals.pl Autoremoval data is generated by: https://salsa.debian.org/qa/udd/-/blob/master/udd/testing_autoremovals_gatherer.pl From noreply at release.debian.org Sun Feb 1 04:39:26 2026 From: noreply at release.debian.org (Debian testing autoremoval watch) Date: Sun, 01 Feb 2026 04:39:26 +0000 Subject: [Pkg-javascript-devel] node-hsluv is marked for autoremoval from testing Message-ID: node-hsluv 0.1.0+dfsg1-3 is marked for autoremoval from testing on 2026-03-01 It (build-)depends on packages with these RC bugs: 1125242: aflplusplus: build-depends on gcc-multilib [s390x], which will get removed https://bugs.debian.org/1125242 For more information on the autoremoval process, including hints to prevent autoremoval can be found on the wiki: https://wiki.debian.org/Autoremoval This mail is generated by: https://salsa.debian.org/release-team/release-tools/-/blob/master/mailer/mail_autoremovals.pl Autoremoval data is generated by: https://salsa.debian.org/qa/udd/-/blob/master/udd/testing_autoremovals_gatherer.pl From carnil at debian.org Sun Feb 1 07:12:54 2026 From: carnil at debian.org (Salvatore Bonaccorso) Date: Sun, 01 Feb 2026 08:12:54 +0100 Subject: [Pkg-javascript-devel] Bug#1126747: angular.js: CVE-2026-22610 Message-ID: <176992997409.2901432.3912400074185383800.reportbug@eldamar.lan> Source: angular.js Version: 1.8.3-3 Severity: important Tags: security upstream Forwarded: https://github.com/angular/angular/pull/66318 X-Debbugs-Cc: carnil at debian.org, Debian Security Team Hi, The following vulnerability was published for angular.js. Note, I'm not certain the issue has not been introduced only after the version in Debian. CVE-2026-22610[0]: | Angular is a development platform for building mobile and desktop | web applications using TypeScript/JavaScript and other languages. | Prior to versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0, a | cross-site scripting (XSS) vulnerability has been identified in the | Angular Template Compiler. The vulnerability exists because | Angular?s internal sanitization schema fails to recognize the href | and xlink:href attributes of SVG