{"id":11037,"date":"2019-11-10T23:17:35","date_gmt":"2019-11-10T22:17:35","guid":{"rendered":"https:\/\/gambaru.de\/blog\/?p=11037"},"modified":"2019-11-10T23:24:36","modified_gmt":"2019-11-10T22:24:36","slug":"my-free-software-activities-in-october-2019","status":"publish","type":"post","link":"https:\/\/gambaru.de\/blog\/2019\/11\/10\/my-free-software-activities-in-october-2019\/","title":{"rendered":"My Free Software Activities in October 2019"},"content":{"rendered":"\n<p>Welcome to gambaru.de. Here is my monthly report that covers what I have been doing for Debian. If you're interested in Java, Games and LTS topics, this might be interesting for you.<\/p>\n\n\n\n<h2>Debian Games<\/h2>\n\n\n\n<ul><li>Python 3 ports: I reviewed and sponsored <a href=\"https:\/\/tracker.debian.org\/pkg\/krank\">krank<\/a> and <a href=\"https:\/\/tracker.debian.org\/pkg\/solarwolf\">solarwolf<\/a> for Reiner Herrmann. Thanks to his diligent work two more Python games were ported to Python 3. He also packaged a new upstream release of <a href=\"https:\/\/tracker.debian.org\/pkg\/hyperrogue\">hyperrogue<\/a> and improved the build system. Less memory is required to build hyperrogue now and some buildd are thankful for that.<\/li><li>The <a href=\"https:\/\/bugs.debian.org\/cgi-bin\/bugreport.cgi?bug=941027\">bullet transition<\/a> got finally approved and completed successfully.<\/li><li>I uploaded a new version of <a href=\"https:\/\/tracker.debian.org\/pkg\/pygame-sdl2\">pygame-sdl2<\/a> to experimental which supports Python 3 now. However the library is still exclusively needed for <a href=\"https:\/\/tracker.debian.org\/pkg\/renpy\">renpy<\/a> but upstream hasn't finished the porting work to Python 3 yet. Hopefully this will be done next year. That means the new version of renpy which I also packaged this month still depends on Python 2.<\/li><li>I fixed two bugs in <a href=\"https:\/\/tracker.debian.org\/pkg\/freeciv\">Freeciv<\/a>, the famous strategy game, by replacing fonts-noto-cjk with fonts-unfonts-core. (<a href=\"https:\/\/bugs.debian.org\/cgi-bin\/bugreport.cgi?bug=934588\">#934588<\/a>) The latter fonts looks apparently better on ordinary screens. The second one was simple to fix, I just had to remove an unneeded Python 2 build-dependency. (<a href=\"https:\/\/bugs.debian.org\/cgi-bin\/bugreport.cgi?bug=936553\">#936553<\/a>)<\/li><li>The strategy game <a href=\"https:\/\/tracker.debian.org\/pkg\/asc\">asc<\/a>, a neat clone of <a href=\"https:\/\/en.wikipedia.org\/wiki\/Battle_Isle\">Battle Isle 2<\/a>, also needed some attention this month. I had to replace libwxgtk3.0-dev with libwxgtk3.0-gtk3-dev. (#943439)<\/li><li>I did a QA upload of <a href=\"https:\/\/tracker.debian.org\/pkg\/open-invaders\">open-invaders<\/a> because the maintainer email address was bouncing. The game needs a new maintainer.<\/li><\/ul>\n\n\n\n<h2>Debian Java<\/h2>\n\n\n\n<ul><li>A new version of <a href=\"https:\/\/tracker.debian.org\/pkg\/libhibernate-validator-java\">libhibernate-validator-java<\/a> <a href=\"https:\/\/bugs.debian.org\/942507\">broke pdfsam<\/a> in unstable. Fortunately the library couldn't migrate to testing before the bug was reported. I haven't completely figured out yet how to address this in pdfsam.<\/li><li>I also packaged new upstream versions of <a href=\"https:\/\/tracker.debian.org\/pkg\/jackson-jr\">jackson-jr<\/a>, <a href=\"https:\/\/tracker.debian.org\/pkg\/jackson-dataformat-xml\">jackson-dataformat-xml<\/a>, <a href=\"https:\/\/tracker.debian.org\/pkg\/jackson-datatype-joda\">jackson-datatype-joda<\/a>, <a href=\"https:\/\/tracker.debian.org\/pkg\/jboss-xnio\">jboss-xnio<\/a> and <a href=\"https:\/\/tracker.debian.org\/pkg\/objenesis\">objenesis<\/a>.<\/li><li>I prepared a security update of jackson-databind for Stretch and Buster released as <a href=\"https:\/\/lists.debian.org\/debian-security-announce\/2019\/msg00191.html\">DSA-4542-1<\/a>. <\/li><\/ul>\n\n\n\n<h2>Misc<\/h2>\n\n\n\n<ul><li>I packaged a new version of <a href=\"https:\/\/tracker.debian.org\/pkg\/privacybadger\">privacybadger<\/a>, and backported <a href=\"https:\/\/tracker.debian.org\/pkg\/ublock-origin\">ublock-origin&nbsp;<\/a> to Stretch and Buster because the addon was incompatible with the latest Firefox ESR release.<\/li><\/ul>\n\n\n\n<h2>Debian LTS<\/h2>\n\n\n\n<p>This was my 44. month as a paid contributor and I have been paid to work 22,75 hours on <a href=\"https:\/\/wiki.debian.org\/LTS\/\">Debian LTS<\/a>, a project started by <a href=\"https:\/\/raphaelhertzog.com\">Rapha\u00ebl Hertzog<\/a>. In that time I did the following:<\/p>\n\n\n\n<ul><li>From 14.10.2019 until 20.10.2019 and from 28.10.2019 until 03.11.2019 I was in charge of our LTS frontdesk. I investigated and triaged CVE in wordpress, ncurses, opencv, pillow, poppler, golang, gdal, lz4, python-reportlab, ruby-haml, vips, rdesktop, modsecurity-crs, zabbix, polarssl and tika.<\/li><li><a href=\"https:\/\/lists.debian.org\/debian-lts-announce\/2019\/10\/msg00023.html\">DLA-1960-1<\/a>. Issued a security update for wordpress fixing 7 CVE.<\/li><li><a href=\"https:\/\/lists.debian.org\/debian-lts-announce\/2019\/10\/msg00027.html\">DLA-1966-1<\/a>. Issued a security update for aspell fixing 1 CVE.<\/li><li><a href=\"https:\/\/lists.debian.org\/debian-lts-announce\/2019\/10\/msg00037.html\">DLA-1973-1<\/a>. Issued a security update for libxslt fixing 1 CVE.<\/li><li><a href=\"https:\/\/lists.debian.org\/debian-lts-announce\/2019\/10\/msg00041.html\">DLA-1978-1<\/a>. Issued a security update for python-ecdsa fixing 2 CVE.<\/li><li><a href=\"https:\/\/lists.debian.org\/debian-lts-announce\/2019\/11\/msg00002.html\">DLA-1982-1<\/a>. Issued a security update for openafs fixing 2 CVE.<\/li><li>I triaged 17 CVE in libgig and forwarded the result upstream. After the investigation I decided to mark these issues as no-dsa because all in all the security risk was low. (<a href=\"https:\/\/bugs.debian.org\/cgi-bin\/bugreport.cgi?bug=931309\">#931309<\/a>)<\/li><\/ul>\n\n\n\n<h2>ELTS<\/h2>\n\n\n\n<p>Extended Long Term Support (<a href=\"https:\/\/wiki.debian.org\/LTS\/Extended\">ELTS<\/a>) is a project led by <a href=\"https:\/\/www.freexian.com\/\">Freexian<\/a> to further extend the lifetime of Debian releases. It is not an official Debian project but all Debian users benefit from it without cost. The current ELTS release is Debian 7 \"Wheezy\". This was my seventeenth month and I have been assigned to work 15 hours on ELTS plus five hours from September. I used 8 of them for the following:<\/p>\n\n\n\n<ul><li><a href=\"https:\/\/deb.freexian.com\/extended-lts\/updates\/ela-185-1-libxslt\/\">ELA-185-1<\/a>. Issued a security update for libxslt fixing 1 CVE.<\/li><li><a href=\"https:\/\/deb.freexian.com\/extended-lts\/updates\/ela-186-1-libssh2\/\">ELA-186-1<\/a>. Issued a security update for libssh2 fixing 1 CVE.<\/li><li><a href=\"https:\/\/deb.freexian.com\/extended-lts\/updates\/ela-187-1-cpio\/\">ELA-187-1<\/a>. Issued a security update for cpio fixing 1 CVE. The update was prepared by Ola Lundqvist.<\/li><li><a href=\"https:\/\/deb.freexian.com\/extended-lts\/updates\/ela-188-1-djvulibre\/\">ELA-188-1<\/a>. Issued a security update for djvulibre fixing 1 CVE.<\/li><li>I worked on OpenJDK 7. I contacted upstream and asked for a new IcedTea release on which we rely for packaging new upstream releases of OpenJDK. The release is still delayed.<\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Welcome to gambaru.de. Here is my monthly report that covers what I have been doing for Debian. If you&#8217;re interested in Java, Games and LTS topics, this might be interesting for you. Debian Games Python 3 ports: I reviewed and sponsored krank and solarwolf for Reiner Herrmann. Thanks to his diligent work two more Python &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/gambaru.de\/blog\/2019\/11\/10\/my-free-software-activities-in-october-2019\/\" class=\"more-link\"><span class=\"screen-reader-text\">\u201eMy Free Software Activities in October 2019\u201c<\/span> weiterlesen<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[5],"tags":[53,68,155],"_links":{"self":[{"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/posts\/11037"}],"collection":[{"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/comments?post=11037"}],"version-history":[{"count":5,"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/posts\/11037\/revisions"}],"predecessor-version":[{"id":11042,"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/posts\/11037\/revisions\/11042"}],"wp:attachment":[{"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/media?parent=11037"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/categories?post=11037"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/tags?post=11037"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}