<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://dev1galaxy.org/extern.php?action=feed&amp;tid=6276&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / Security updates for forked packages? (e.g. xorg-server)]]></title>
		<link>https://dev1galaxy.org/viewtopic.php?id=6276</link>
		<description><![CDATA[The most recent posts in Security updates for forked packages? (e.g. xorg-server).]]></description>
		<lastBuildDate>Sun, 24 Dec 2023 05:24:30 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: Security updates for forked packages? (e.g. xorg-server)]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=46482#p46482</link>
			<description><![CDATA[<p>You are correct. This is what my Daedalus-based Refracta system is showing:</p><div class="codebox"><pre class="vscroll"><code>$ aptitude show xserver-xorg-core
Package: xserver-xorg-core               
Version: 2:21.1.7-3+deb12u2devuan1
State: installed
Automatically installed: yes
Priority: optional
Section: x11
Maintainer: Devuan Developers &lt;devuan-dev@lists.dyne.org&gt;
Architecture: amd64
Uncompressed Size: 3,907 k
Depends: xserver-common (&gt;= 2:21.1.7-3+deb12u2devuan1), keyboard-configuration, udev (&gt;= 149), libegl1, libaudit1 (&gt;= 1:2.2.1),
         libbsd0 (&gt;= 0.7.0), libc6 (&gt;= 2.35), libdrm2 (&gt;= 2.4.66), libepoxy0 (&gt;= 1.5.4), libeudev1 (&gt;= 3.2.12), libgbm1 (&gt;=
         17.1.0~rc2), libgcrypt20 (&gt;= 1.10.0), libgl1, libpciaccess0 (&gt;= 0.12.902), libpixman-1-0 (&gt;= 0.30.0), libseat1 (&gt;= 0.5.0),
         libselinux1 (&gt;= 3.1~), libunwind8, libxau6 (&gt;= 1:1.0.9), libxcvt0 (&gt;= 0.1.0), libxdmcp6, libxfont2 (&gt;= 1:2.0.1),
         libxshmfence1
Recommends: libgl1-mesa-dri (&gt;= 7.10.2-4), xcvt
Suggests: xfonts-100dpi | xfonts-75dpi, xfonts-scalable
Conflicts: xserver-xorg-input-evtouch, xserver-xorg-video-modesetting
Breaks: libgl1-mesa-dri (&lt; 18.0.5), systemd (&lt; 226-4~), xserver-xorg (&lt; 1:7.7+10~)
Replaces: xserver-xorg (&lt; 1:7.7+10~), xserver-xorg-video-modesetting
Provides: xorg-input-abi-24, xorg-video-abi-25, xserver-xorg-video-modesetting
Description: Xorg X server - core server
 The Xorg X server is an X server for several architectures and operating systems, which is derived from the XFree86 4.x series of X
 servers. 
 
 The Xorg server supports most modern graphics hardware from most vendors, and supersedes all XFree86 X servers. 
 
 More information about X.Org can be found at: &lt;URL:https://www.x.org&gt; 
 
 This package is built from the X.org xserver module.
Homepage: https://www.x.org/</code></pre></div><p>I also checked the apt cache for recent debs:</p><div class="codebox"><pre><code>$ ls -l /var/cache/apt/archives |grep xserver-xorg
-rw-r--r-- 1 root root  1365092 Oct 26 09:56 xserver-xorg-core_2%3a21.1.7-3+deb12u2devuan1_amd64.deb
-rw-r--r-- 1 root root   122432 Feb 12  2022 xserver-xorg-input-evdev_1%3a2.10.6-2+b1_amd64.deb
-rw-r--r-- 1 root root    69248 Feb 12  2022 xserver-xorg-input-mouse_1%3a1.9.3-1+b1_amd64.deb
-rw-r--r-- 1 root root   214892 Mar 23  2023 xserver-xorg-input-synaptics_1.9.2-1+b1_amd64.deb</code></pre></div><p>This is the relevant Debian security advisory:<br /><a href="https://www.debian.org/security/2023/dsa-5576-2" rel="nofollow">https://www.debian.org/security/2023/dsa-5576-2</a></p><p>According to that web page, the <strong>xserver-xorg-core</strong> package in Daedalus is two versions behind.</p>]]></description>
			<author><![CDATA[dummy@example.com (pcalvert)]]></author>
			<pubDate>Sun, 24 Dec 2023 05:24:30 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=46482#p46482</guid>
		</item>
		<item>
			<title><![CDATA[Re: Security updates for forked packages? (e.g. xorg-server)]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=46479#p46479</link>
			<description><![CDATA[<p>That shows just <span class="bbc">xorg-server-source</span>, but the runtime pieces have names like <span class="bbc">xserver-xorg-*</span>. And the <span class="bbc">xserver-xorg-core</span> in Daedalus is <span class="bbc">2:21.1.7-3+deb12u2devuan1</span>.</p>]]></description>
			<author><![CDATA[dummy@example.com (semil)]]></author>
			<pubDate>Sun, 24 Dec 2023 00:01:54 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=46479#p46479</guid>
		</item>
		<item>
			<title><![CDATA[Re: Security updates for forked packages? (e.g. xorg-server)]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=46474#p46474</link>
			<description><![CDATA[<p>It looks like <span class="bbc">xorg-server</span> comes <span class="bbu"><a href="https://pkginfo.devuan.org/cgi-bin/policy-query.html?c=package&amp;q=xorg-server*&amp;x=submit" rel="nofollow">directly from Debian</a></span> so you shouldn&#039;t have to do anything special if you <span class="bbc">sources.list</span> is in order.</p>]]></description>
			<author><![CDATA[dummy@example.com (golinux)]]></author>
			<pubDate>Sat, 23 Dec 2023 20:48:07 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=46474#p46474</guid>
		</item>
		<item>
			<title><![CDATA[Security updates for forked packages? (e.g. xorg-server)]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=46470#p46470</link>
			<description><![CDATA[<p>xorg-server had vulnerabilities fixed in Debian about six days ago. I know Devuan’s is forked because of the libseat situation.</p><p>In such a case, is “TODO: merge xorg-server security fixes” added to some list of items somewhere, or…?</p>]]></description>
			<author><![CDATA[dummy@example.com (semil)]]></author>
			<pubDate>Sat, 23 Dec 2023 19:31:41 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=46470#p46470</guid>
		</item>
	</channel>
</rss>
