[Pkg-puppet-devel] Puppet security fix for squeeze-backports

micah micah at debian.org
Wed Jul 3 17:59:40 UTC 2013


Russ Allbery <rra at debian.org> writes:

> Our Puppet master servers (and Puppet CA, although I'm not sure if it's
> affected?) are still on squeeze.  Would it be possible to get a backport
> of 2.7.18-5 to squeeze-backports?
>
> Let me know if it's something I should just try to do myself.  I'm not
> horribly familiar with backporting of Ruby packages, but I can give it a
> shot.

I tried to do this backport, but have been unable to succeed, primarily
because the new version that fixes this issue has a new dependency on
ruby-rspec. ruby-rspec is not in squeeze, and backporting it is very
painful (there are unsatisfied requirements on some thorny things like
specific ruby1.9.1 versions that also aren't in squeeze).

I'm not sure what to do about this.

The ruby-rspec build-dep was removed a few days ago by Stig as it wasn't
necessary for the newer versions, but it is still there in the Wheezy
security upload.

micah



More information about the Pkg-puppet-devel mailing list