{"id":10273,"date":"2018-02-06T18:23:02","date_gmt":"2018-02-06T17:23:02","guid":{"rendered":"https:\/\/gambaru.de\/blog\/?p=10273"},"modified":"2018-02-06T18:23:02","modified_gmt":"2018-02-06T17:23:02","slug":"my-free-software-activities-in-january-2018","status":"publish","type":"post","link":"https:\/\/gambaru.de\/blog\/2018\/02\/06\/my-free-software-activities-in-january-2018\/","title":{"rendered":"My Free Software Activities in January 2018"},"content":{"rendered":"<p>Welcome to gambaru.de. Here is my monthly report that covers what I have been doing for Debian. If you're interested in Java, Games and LTS topics, this might be interesting for you.<\/p>\n<h2>Debian Games<\/h2>\n<ul>\n<li><strong>The state of Debian Games:<\/strong> We have created a new <a href=\"https:\/\/salsa.debian.org\/games-team\">games-team group at salsa.debian.org<\/a>. If you are interested in maintaining games or related projects then we're looking forward to see you there. A couple of Gnome related games are <a href=\"https:\/\/bugs.debian.org\/cgi-bin\/pkgreport.cgi?which=maint&amp;data=pkg-games-devel%40lists.alioth.debian.org&amp;archive=no&amp;pend-exc=done&amp;sev-inc=critical&amp;sev-inc=grave&amp;sev-inc=serious\">at risk of being removed<\/a> from Debian. If you are interested in a challenge and want to port them to Gnome 3, we would very much like to hear from you too.<\/li>\n<li>I reviewed and sponsored new upstream versions of <a href=\"https:\/\/tracker.debian.org\/pkg\/simutrans-pak64\">simutrans-pak64<\/a> and <a href=\"https:\/\/tracker.debian.org\/pkg\/simutrans\">simutrans<\/a> for J\u00f6rg Frings-F\u00fcrst as well as <a href=\"https:\/\/tracker.debian.org\/pkg\/openmw\">openmw<\/a>, <a href=\"https:\/\/tracker.debian.org\/pkg\/mygui\">mygui<\/a>, <a href=\"https:\/\/tracker.debian.org\/pkg\/wildmidi\">wildmidi<\/a> and <a href=\"https:\/\/tracker.debian.org\/pkg\/openal\">openal<\/a> for Bret Curtis. Later I could also upload <a href=\"https:\/\/tracker.debian.org\/pkg\/hexalate\">hexalate<\/a> for Unit193 and <a href=\"https:\/\/tracker.debian.org\/pkg\/pegsolitaire\">pegsolitaire<\/a> for Juhani Numminen. Great job by Juhani who became the new upstream maintainer of pegsolitaire and saved the game from being removed from Debian.<\/li>\n<li>I for myself packaged new upstream releases of <a href=\"https:\/\/tracker.debian.org\/pkg\/springlobby\">springlobby<\/a>, <a href=\"https:\/\/tracker.debian.org\/pkg\/peg-e\">peg-e<\/a>, <a href=\"https:\/\/tracker.debian.org\/pkg\/pygame-sdl2\">pygame-sdl2<\/a>, <a href=\"https:\/\/tracker.debian.org\/pkg\/freeciv\">freeciv<\/a>, <a href=\"https:\/\/tracker.debian.org\/pkg\/renpy\">renpy<\/a> and <a href=\"https:\/\/tracker.debian.org\/pkg\/cube2\">cube2<\/a>. I was a bit surprised to see upstream activity for the Sauerbraten engine again. Will we see a new major release this year?<\/li>\n<li>Peter Green provided a patch to fix Debian RC bug #887929 in <a href=\"https:\/\/tracker.debian.org\/pkg\/trigger-rally\">trigger-rally<\/a> which I gladly accepted.<\/li>\n<li>I also fixed RC bug #885761 in <a href=\"https:\/\/tracker.debian.org\/pkg\/langdrill\">langdrill.<\/a><\/li>\n<\/ul>\n<h2>Debian Java<\/h2>\n<ul>\n<li>New upstream versions this month: <a href=\"https:\/\/tracker.debian.org\/pkg\/mediathekview\">mediathekview<\/a>, <a href=\"https:\/\/tracker.debian.org\/pkg\/libsmali-java\">libsmali-java<\/a>, <a href=\"https:\/\/tracker.debian.org\/pkg\/apktool\">apktool<\/a>, <a href=\"https:\/\/tracker.debian.org\/pkg\/wildfly-common\">wildfly-common<\/a>, <a href=\"https:\/\/tracker.debian.org\/pkg\/bouncycastle\">bouncycastle<\/a>, <a href=\"https:\/\/tracker.debian.org\/pkg\/bcel\">bcel<\/a>, <a href=\"https:\/\/tracker.debian.org\/pkg\/undertow\">undertow<\/a>, <a href=\"https:\/\/tracker.debian.org\/pkg\/commons-io\">commons-io<\/a>, <a href=\"https:\/\/tracker.debian.org\/pkg\/jcifs\">jcifs<\/a>, <a href=\"https:\/\/tracker.debian.org\/pkg\/libjide-oss-java\">libjide-oss-java<\/a>, <a href=\"https:\/\/tracker.debian.org\/pkg\/sweethome3d\">sweethome3d<\/a> and <a href=\"https:\/\/tracker.debian.org\/pkg\/sweethome3d-furniture-editor\">sweethome3d-furniture-editor<\/a>.<\/li>\n<li>I introduced <a href=\"https:\/\/tracker.debian.org\/pkg\/jboss-threads\">jboss-threads<\/a> to Debian because it is a new build-dependency of <a href=\"https:\/\/tracker.debian.org\/pkg\/jboss-xnio\">jboss-xnio<\/a>. Thanks FTP team for quickly processing the package!<\/li>\n<li>I fixed a couple of security issues in <a href=\"https:\/\/tracker.debian.org\/pkg\/plexus-utils\">plexus-utils<\/a> (CVE-2017-1000487), <a href=\"https:\/\/tracker.debian.org\/pkg\/libhibernate-validator-java\">libhibernate-validator-java<\/a> (CVE-2017-7536) and <a href=\"https:\/\/tracker.debian.org\/pkg\/lucene-solr\">lucene-solr<\/a> (CVE-2017-3163, CVE-2017-12629) and enabled <a href=\"https:\/\/tracker.debian.org\/pkg\/libpdfbox2-java\">libpdfbox2-java<\/a> to build from source again (#887479).<\/li>\n<li>This month we received another report about security issues in <a href=\"https:\/\/tracker.debian.org\/pkg\/jackson-databind\">jackson-databind<\/a>. I resolved this by upgrading to upstream version 2.9.4 and since the jackson stack is usually upgraded in lockstep I ended up with additional uploads for nine different packages.<\/li>\n<li><strong>Oh Java 9:<\/strong> There are less and less low-hanging fruits by now. <a href=\"https:\/\/bugs.debian.org\/cgi-bin\/pkgreport.cgi?users=debian-java@lists.debian.org;tag=default-java9\">Roughly 50 bugs<\/a> are still open which prevent the switch to OpenJDK 9 as the default JDK\/JRE in Debian. This month I fixed or provided patches for <a href=\"https:\/\/tracker.debian.org\/pkg\/nescc\">nescc<\/a>, <a href=\"https:\/\/tracker.debian.org\/pkg\/openjpeg2\">openjpeg2<\/a>, <a href=\"https:\/\/tracker.debian.org\/pkg\/sonic\">sonic<\/a>, <a href=\"https:\/\/tracker.debian.org\/pkg\/ssvnc\">ssvnc<\/a> and <a href=\"https:\/\/tracker.debian.org\/pkg\/pegasus-wms\">pegasus-wms<\/a>. I also investigated <a href=\"https:\/\/tracker.debian.org\/pkg\/salliere\">salliere<\/a> and <a href=\"https:\/\/tracker.debian.org\/pkg\/pescetti\">pescetti.<\/a> Furthermore I requested the removal of obsolete packages from Debian namely libpam4j, ha-jdbc, tyger-types and libgroboutils-java.<\/li>\n<\/ul>\n<h2>Debian LTS<\/h2>\n<p>This was my twenty-third month as a paid contributor and I have been paid to work 18,25 hours on <a href=\"https:\/\/wiki.debian.org\/LTS\/\">Debian LTS<\/a>, a project started by <a href=\"https:\/\/raphaelhertzog.com\">Rapha\u00ebl Hertzog<\/a>. In that time I did the following:<\/p>\n<ul>\n<li>From 08.01.2018 until 14.01.2018 I was in charge of our LTS frontdesk. I investigated and triaged CVE in libhibernate-validator-java, libkohana2-php, xbmc, jasperreports, transmission, wireshark, osc, xmltooling, php5 and openocd.<\/li>\n<li><a href=\"https:\/\/lists.debian.org\/debian-lts-announce\/2018\/01\/msg00015.html\">DLA-1241-1<\/a>. Issued a security update for libkohana2-php fixing 1 CVE.<\/li>\n<li><a href=\"https:\/\/lists.debian.org\/debian-lts-announce\/2018\/01\/msg00016.html\">DLA-1242-1<\/a>. Issued a security update for xmltooling fixing 1 CVE.<\/li>\n<li><a href=\"https:\/\/lists.debian.org\/debian-lts-announce\/2018\/01\/msg00019.html\">DLA-1243-1<\/a>. Issued a security update for xbmc fixing 1 CVE.<\/li>\n<li><a href=\"https:\/\/lists.debian.org\/debian-lts-announce\/2018\/01\/msg00025.html\">DLA-1251-1<\/a>. Issued a security update for php5 fixing 1 CVE.<\/li>\n<li><a href=\"https:\/\/lists.debian.org\/debian-lts-announce\/2018\/01\/msg00027.html\">DLA-1253-1<\/a>. Issued a security update for openocd fixing 1 CVE.<\/li>\n<li><a href=\"https:\/\/lists.debian.org\/debian-lts-announce\/2018\/01\/msg00028.html\">DLA-1254-1<\/a>. Issued a security update for lucene-solr fixing 1 CVE.<\/li>\n<li><a href=\"https:\/\/lists.debian.org\/debian-lts-announce\/2018\/01\/msg00039.html\">DLA-1264-1<\/a>. Issued a security update for unbound fixing 1 CVE.<\/li>\n<li><a href=\"https:\/\/lists.debian.org\/debian-lts-announce\/2018\/01\/msg00040.html\">DLA-1265-1<\/a>. Issued a security update for krb5 fixing 6 CVE.<\/li>\n<\/ul>\n<h2>Misc<\/h2>\n<ul>\n<li>I reviewed a patch for <a href=\"https:\/\/tracker.debian.org\/pkg\/byzanz\">byzanz<\/a> (#886439) but wasn't really happy with the result.<\/li>\n<li>I released version 1.4.10 of <a href=\"https:\/\/tracker.debian.org\/pkg\/imlib2\">imlib2.<\/a><\/li>\n<li>The discussion about a new reportbug feature gathered momentum in <a href=\"https:\/\/bugs.debian.org\/cgi-bin\/bugreport.cgi?bug=878088\">#878088<\/a> and I am confident now that we can conclude this issue in February.<\/li>\n<\/ul>\n<p>Thanks for reading and see you next time.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Welcome to gambaru.de. Here is my monthly report that covers what I have been doing for Debian. If you&#8217;re interested in Java, Games and LTS topics, this might be interesting for you. Debian Games The state of Debian Games: We have created a new games-team group at salsa.debian.org. If you are interested in maintaining games &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/gambaru.de\/blog\/2018\/02\/06\/my-free-software-activities-in-january-2018\/\" class=\"more-link\"><span class=\"screen-reader-text\">\u201eMy Free Software Activities in January 2018\u201c<\/span> weiterlesen<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[4],"tags":[53,68,155],"_links":{"self":[{"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/posts\/10273"}],"collection":[{"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/comments?post=10273"}],"version-history":[{"count":0,"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/posts\/10273\/revisions"}],"wp:attachment":[{"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/media?parent=10273"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/categories?post=10273"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/tags?post=10273"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}