Activity log for bug #1187262

Date Who What changed Old value New value Message
2013-06-04 07:00:10 James Page bug added bug
2013-06-04 07:00:23 James Page bug task added libv8 (Ubuntu)
2013-06-04 07:00:33 James Page bug task added snowball (Ubuntu)
2013-06-04 07:00:43 James Page bug task added gyp (Ubuntu)
2013-06-04 07:08:47 James Page description MIR for mongodb >> mongodb << Availability: In universe for several releases. Rationale: Preferred data storage platform for Ceilometer (core OpenStack project) and a key component juju-core. Security: Two security issues, both resolved upstream. native helper security issue only impacts earlier versions of MongoDB - 2.4.x uses libv8 instead of spidermonkey and does not have this function. QA: Works out-of-the-box from packaging. Package ships a test suite (smoke) which is executed on all target platforms. Generally well maintained in Debian and in Ubuntu (server team). Issue with OpenSSL license compatibility needs to be resolved (upstream working on this). Dependencies: All in main aside from libv8, snowball and gyp Maintenance: Upstream push out minor point releases for bug fixes (MRE will be applied for). Packaging generally in good shape aside from static linking of client binaries (being worked on in Debian). >> libv8 << Availability: In universe for several releases. Rationale: Dependency for MongoDB embedded scripting engine. Security:
2013-06-04 07:14:03 James Page description >> mongodb << Availability: In universe for several releases. Rationale: Preferred data storage platform for Ceilometer (core OpenStack project) and a key component juju-core. Security: Two security issues, both resolved upstream. native helper security issue only impacts earlier versions of MongoDB - 2.4.x uses libv8 instead of spidermonkey and does not have this function. QA: Works out-of-the-box from packaging. Package ships a test suite (smoke) which is executed on all target platforms. Generally well maintained in Debian and in Ubuntu (server team). Issue with OpenSSL license compatibility needs to be resolved (upstream working on this). Dependencies: All in main aside from libv8, snowball and gyp Maintenance: Upstream push out minor point releases for bug fixes (MRE will be applied for). Packaging generally in good shape aside from static linking of client binaries (being worked on in Debian). >> libv8 << Availability: In universe for several releases. Rationale: Dependency for MongoDB embedded scripting engine. Security: >> mongodb << Availability: In universe for several releases. Rationale: Preferred data storage platform for Ceilometer (core OpenStack project) and a key component juju-core. Security: Two security issues, both resolved upstream. native helper security issue only impacts earlier versions of MongoDB - 2.4.x uses libv8 instead of spidermonkey and does not have this function. QA: Works out-of-the-box from packaging. Package ships a test suite (smoke) which is executed on all target platforms. Generally well maintained in Debian and in Ubuntu (server team). Issue with OpenSSL license compatibility needs to be resolved (upstream working on this). Dependencies: All in main aside from libv8, snowball and gyp Maintenance: Upstream push out minor point releases for bug fixes (MRE will be applied for). Packaging generally in good shape aside from static linking of client binaries (being worked on in Debian). >> libv8 << Availability: In universe for several releases. Rationale: Dependency for MongoDB embedded scripting engine. Security: Lots of CVE's: http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=v8 I suspect that alot of these relate to the use of v8 in Chrome. However as this is a core component of chrome, we can reasonably expect Google to be responsive to security issues in the future. QA: Package works. Regression tests executed during package build. Dependencies: Use gyp for build system. Maintenance: Well maintained in Debian (supports nodejs as well). >> gyp <<
2013-06-04 08:09:30 James Page description >> mongodb << Availability: In universe for several releases. Rationale: Preferred data storage platform for Ceilometer (core OpenStack project) and a key component juju-core. Security: Two security issues, both resolved upstream. native helper security issue only impacts earlier versions of MongoDB - 2.4.x uses libv8 instead of spidermonkey and does not have this function. QA: Works out-of-the-box from packaging. Package ships a test suite (smoke) which is executed on all target platforms. Generally well maintained in Debian and in Ubuntu (server team). Issue with OpenSSL license compatibility needs to be resolved (upstream working on this). Dependencies: All in main aside from libv8, snowball and gyp Maintenance: Upstream push out minor point releases for bug fixes (MRE will be applied for). Packaging generally in good shape aside from static linking of client binaries (being worked on in Debian). >> libv8 << Availability: In universe for several releases. Rationale: Dependency for MongoDB embedded scripting engine. Security: Lots of CVE's: http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=v8 I suspect that alot of these relate to the use of v8 in Chrome. However as this is a core component of chrome, we can reasonably expect Google to be responsive to security issues in the future. QA: Package works. Regression tests executed during package build. Dependencies: Use gyp for build system. Maintenance: Well maintained in Debian (supports nodejs as well). >> gyp << >> mongodb << Availability: In universe for several releases. Rationale: Preferred data storage platform for Ceilometer (core OpenStack project) and a key component juju-core. Security: Two security issues, both resolved upstream. native helper security issue only impacts earlier versions of MongoDB - 2.4.x uses libv8 instead of spidermonkey and does not have this function. QA: Works out-of-the-box from packaging. Package ships a test suite (smoke) which is executed on all target platforms. Generally well maintained in Debian and in Ubuntu (server team). Issue with OpenSSL license compatibility needs to be resolved (upstream working on this). Dependencies: All in main aside from libv8, snowball and gyp Maintenance: Upstream push out minor point releases for bug fixes (MRE will be applied for). Packaging generally in good shape aside from static linking of client binaries (being worked on in Debian). >> libv8 << Availability: In universe for several releases. Rationale: Dependency for MongoDB embedded scripting engine. Security: Lots of CVE's: http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=v8 I suspect that alot of these relate to the use of v8 in Chrome. However as this is a core component of chrome, we can reasonably expect Google to be responsive to security issues in the future. QA: Package works. Regression tests executed during package build. Dependencies: Use gyp for build system. Maintenance: Well maintained in Debian (supports nodejs as well). >> gyp << Availability: In universe. Rationale: Build dependency for libv8 Security: No CVE's found QA: Works from packaging, no test suite execution during build. Dependencies: All in main Maintenance: Until recently not that well maintained in Debian; however nodejs maintainer seems to be picking things up now (see version in saucy which refreshed the package considerably).
2013-06-04 08:10:37 James Page description >> mongodb << Availability: In universe for several releases. Rationale: Preferred data storage platform for Ceilometer (core OpenStack project) and a key component juju-core. Security: Two security issues, both resolved upstream. native helper security issue only impacts earlier versions of MongoDB - 2.4.x uses libv8 instead of spidermonkey and does not have this function. QA: Works out-of-the-box from packaging. Package ships a test suite (smoke) which is executed on all target platforms. Generally well maintained in Debian and in Ubuntu (server team). Issue with OpenSSL license compatibility needs to be resolved (upstream working on this). Dependencies: All in main aside from libv8, snowball and gyp Maintenance: Upstream push out minor point releases for bug fixes (MRE will be applied for). Packaging generally in good shape aside from static linking of client binaries (being worked on in Debian). >> libv8 << Availability: In universe for several releases. Rationale: Dependency for MongoDB embedded scripting engine. Security: Lots of CVE's: http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=v8 I suspect that alot of these relate to the use of v8 in Chrome. However as this is a core component of chrome, we can reasonably expect Google to be responsive to security issues in the future. QA: Package works. Regression tests executed during package build. Dependencies: Use gyp for build system. Maintenance: Well maintained in Debian (supports nodejs as well). >> gyp << Availability: In universe. Rationale: Build dependency for libv8 Security: No CVE's found QA: Works from packaging, no test suite execution during build. Dependencies: All in main Maintenance: Until recently not that well maintained in Debian; however nodejs maintainer seems to be picking things up now (see version in saucy which refreshed the package considerably). >> mongodb << Availability: In universe for several releases. Rationale: Preferred data storage platform for Ceilometer (core OpenStack project) and a key component juju-core. Security: Two security issues, both resolved upstream. native helper security issue only impacts earlier versions of MongoDB - 2.4.x uses libv8 instead of spidermonkey and does not have this function. QA: Works out-of-the-box from packaging. Package ships a test suite (smoke) which is executed on all target platforms. Generally well maintained in Debian and in Ubuntu (server team). Issue with OpenSSL license compatibility needs to be resolved (upstream working on this). Dependencies: All in main aside from libv8, snowball and gyp Maintenance: Upstream push out minor point releases for bug fixes (MRE will be applied for). Packaging generally in good shape aside from static linking of client binaries (being worked on in Debian). >> libv8 << Availability: In universe for several releases. Rationale: Dependency for MongoDB embedded scripting engine. Security: Lots of CVE's: http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=v8 I suspect that alot of these relate to the use of v8 in Chrome. However as this is a core component of chrome, we can reasonably expect Google to be responsive to security issues in the future. QA: Package works. Regression tests executed during package build. Dependencies: Use gyp for build system. Maintenance: Well maintained in Debian (supports nodejs as well). >> gyp << Availability: In universe. Rationale: Build dependency for libv8 Security: No CVE's found QA: Works from packaging, test suite present but not executed during build. Dependencies: All in main Maintenance: Until recently not that well maintained in Debian; however nodejs maintainer seems to be picking things up now (see version in saucy which refreshed the package considerably).
2013-06-04 12:20:28 James Page description >> mongodb << Availability: In universe for several releases. Rationale: Preferred data storage platform for Ceilometer (core OpenStack project) and a key component juju-core. Security: Two security issues, both resolved upstream. native helper security issue only impacts earlier versions of MongoDB - 2.4.x uses libv8 instead of spidermonkey and does not have this function. QA: Works out-of-the-box from packaging. Package ships a test suite (smoke) which is executed on all target platforms. Generally well maintained in Debian and in Ubuntu (server team). Issue with OpenSSL license compatibility needs to be resolved (upstream working on this). Dependencies: All in main aside from libv8, snowball and gyp Maintenance: Upstream push out minor point releases for bug fixes (MRE will be applied for). Packaging generally in good shape aside from static linking of client binaries (being worked on in Debian). >> libv8 << Availability: In universe for several releases. Rationale: Dependency for MongoDB embedded scripting engine. Security: Lots of CVE's: http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=v8 I suspect that alot of these relate to the use of v8 in Chrome. However as this is a core component of chrome, we can reasonably expect Google to be responsive to security issues in the future. QA: Package works. Regression tests executed during package build. Dependencies: Use gyp for build system. Maintenance: Well maintained in Debian (supports nodejs as well). >> gyp << Availability: In universe. Rationale: Build dependency for libv8 Security: No CVE's found QA: Works from packaging, test suite present but not executed during build. Dependencies: All in main Maintenance: Until recently not that well maintained in Debian; however nodejs maintainer seems to be picking things up now (see version in saucy which refreshed the package considerably). >> mongodb << Availability: In universe for several releases. Rationale: Preferred data storage platform for Ceilometer (core OpenStack project) and a key component juju-core. Security: Two security issues, both resolved upstream. native helper security issue only impacts earlier versions of MongoDB - 2.4.x uses libv8 instead of spidermonkey and does not have this function. QA: Works out-of-the-box from packaging. Package ships a test suite (smoke) which is executed on all target platforms. Generally well maintained in Debian and in Ubuntu (server team). Issue with OpenSSL license compatibility needs to be resolved (upstream working on this). Dependencies: All in main aside from libv8, snowball and gyp Maintenance: Upstream push out minor point releases for bug fixes (MRE will be applied for). Packaging generally in good shape aside from static linking of client binaries (being worked on in Debian). >> libv8 << Availability: In universe for several releases. Rationale: Dependency for MongoDB embedded scripting engine. Security: Lots of CVE's: http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=v8 I suspect that alot of these relate to the use of v8 in Chrome. However as this is a core component of chrome, we can reasonably expect Google to be responsive to security issues in the future. QA: Package works. Regression tests executed during package build. Dependencies: Use gyp for build system. Maintenance: Well maintained in Debian (supports nodejs as well). >> gyp << Availability: In universe. Rationale: Build dependency for libv8 Security: No CVE's found QA: Works from packaging, test suite present but not executed during build. Dependencies: All in main Maintenance: Until recently not that well maintained in Debian; however nodejs maintainer seems to be picking things up now (see version in saucy which refreshed the package considerably). >> snowball << Availability: In universe. Rationale: libstemmer is a build and runtime dependency for mongodb > 2.4 Security: No CVE's found QA: Packaging generally looks good - multi-arched. No test suite execution during build process. Maintenance: Debian and Ubuntu hold a pre-release snapshot; not much activity in the last 18 months. Background information: libstemmer provides algorithmic stemmer functions for building natural language search functions.
2013-06-04 12:26:30 James Page description >> mongodb << Availability: In universe for several releases. Rationale: Preferred data storage platform for Ceilometer (core OpenStack project) and a key component juju-core. Security: Two security issues, both resolved upstream. native helper security issue only impacts earlier versions of MongoDB - 2.4.x uses libv8 instead of spidermonkey and does not have this function. QA: Works out-of-the-box from packaging. Package ships a test suite (smoke) which is executed on all target platforms. Generally well maintained in Debian and in Ubuntu (server team). Issue with OpenSSL license compatibility needs to be resolved (upstream working on this). Dependencies: All in main aside from libv8, snowball and gyp Maintenance: Upstream push out minor point releases for bug fixes (MRE will be applied for). Packaging generally in good shape aside from static linking of client binaries (being worked on in Debian). >> libv8 << Availability: In universe for several releases. Rationale: Dependency for MongoDB embedded scripting engine. Security: Lots of CVE's: http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=v8 I suspect that alot of these relate to the use of v8 in Chrome. However as this is a core component of chrome, we can reasonably expect Google to be responsive to security issues in the future. QA: Package works. Regression tests executed during package build. Dependencies: Use gyp for build system. Maintenance: Well maintained in Debian (supports nodejs as well). >> gyp << Availability: In universe. Rationale: Build dependency for libv8 Security: No CVE's found QA: Works from packaging, test suite present but not executed during build. Dependencies: All in main Maintenance: Until recently not that well maintained in Debian; however nodejs maintainer seems to be picking things up now (see version in saucy which refreshed the package considerably). >> snowball << Availability: In universe. Rationale: libstemmer is a build and runtime dependency for mongodb > 2.4 Security: No CVE's found QA: Packaging generally looks good - multi-arched. No test suite execution during build process. Maintenance: Debian and Ubuntu hold a pre-release snapshot; not much activity in the last 18 months. Background information: libstemmer provides algorithmic stemmer functions for building natural language search functions. >> mongodb << Availability: In universe for several releases. Rationale: Preferred data storage platform for Ceilometer (core OpenStack project) and a key component juju-core. Security: Two security issues, both resolved upstream. native helper security issue only impacts earlier versions of MongoDB - 2.4.x uses libv8 instead of spidermonkey and does not have this function. QA: Works out-of-the-box from packaging. Package ships a test suite (smoke) which is executed on all target platforms. Generally well maintained in Debian and in Ubuntu (server team). Issue with OpenSSL license compatibility needs to be resolved (upstream working on this). Dependencies: All in main aside from libv8, snowball and gyp Maintenance: Upstream push out minor point releases for bug fixes (MRE will be applied for). Packaging generally in good shape aside from static linking of client binaries (being worked on in Debian). >> libv8 << Availability: In universe for several releases. Rationale: Dependency for MongoDB embedded scripting engine. Security: Lots of CVE's: http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=v8 I suspect that alot of these relate to the use of v8 in Chrome. However as this is a core component of chrome, we can reasonably expect Google to be responsive to security issues in the future. QA: Package works. Regression tests executed during package build. Dependencies: Use gyp for build system. Maintenance: Well maintained in Debian (supports nodejs as well). >> gyp << Availability: In universe. Rationale: Build dependency for libv8 Security: No CVE's found QA: Works from packaging, test suite present but not executed during build. Dependencies: All in main Maintenance: Until recently not that well maintained in Debian; however nodejs maintainer seems to be picking things up now (see version in saucy which refreshed the package considerably). >> snowball << Availability: In universe. Rationale: libstemmer is a build and runtime dependency for mongodb > 2.4 Security: No CVE's found QA: Packaging generally looks good - multi-arched. Unit test suite executed during package build process. Maintenance: Debian and Ubuntu hold a pre-release snapshot; not much activity in the last 18 months. Background information: libstemmer provides algorithmic stemmer functions for building natural language search functions.
2013-06-04 12:27:09 James Page description >> mongodb << Availability: In universe for several releases. Rationale: Preferred data storage platform for Ceilometer (core OpenStack project) and a key component juju-core. Security: Two security issues, both resolved upstream. native helper security issue only impacts earlier versions of MongoDB - 2.4.x uses libv8 instead of spidermonkey and does not have this function. QA: Works out-of-the-box from packaging. Package ships a test suite (smoke) which is executed on all target platforms. Generally well maintained in Debian and in Ubuntu (server team). Issue with OpenSSL license compatibility needs to be resolved (upstream working on this). Dependencies: All in main aside from libv8, snowball and gyp Maintenance: Upstream push out minor point releases for bug fixes (MRE will be applied for). Packaging generally in good shape aside from static linking of client binaries (being worked on in Debian). >> libv8 << Availability: In universe for several releases. Rationale: Dependency for MongoDB embedded scripting engine. Security: Lots of CVE's: http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=v8 I suspect that alot of these relate to the use of v8 in Chrome. However as this is a core component of chrome, we can reasonably expect Google to be responsive to security issues in the future. QA: Package works. Regression tests executed during package build. Dependencies: Use gyp for build system. Maintenance: Well maintained in Debian (supports nodejs as well). >> gyp << Availability: In universe. Rationale: Build dependency for libv8 Security: No CVE's found QA: Works from packaging, test suite present but not executed during build. Dependencies: All in main Maintenance: Until recently not that well maintained in Debian; however nodejs maintainer seems to be picking things up now (see version in saucy which refreshed the package considerably). >> snowball << Availability: In universe. Rationale: libstemmer is a build and runtime dependency for mongodb > 2.4 Security: No CVE's found QA: Packaging generally looks good - multi-arched. Unit test suite executed during package build process. Maintenance: Debian and Ubuntu hold a pre-release snapshot; not much activity in the last 18 months. Background information: libstemmer provides algorithmic stemmer functions for building natural language search functions. >> mongodb << Availability: In universe for several releases. Rationale: Preferred data storage platform for Ceilometer (core OpenStack project) and a key component juju-core. Security: Two security issues, both resolved upstream. native helper security issue only impacts earlier versions of MongoDB - 2.4.x uses libv8 instead of spidermonkey and does not have this function. QA: Works out-of-the-box from packaging. Package ships a test suite (smoke) which is executed on all target platforms. Generally well maintained in Debian and in Ubuntu (server team). Issue with OpenSSL license compatibility needs to be resolved (upstream working on this). Dependencies: All in main aside from libv8, snowball and gyp Maintenance: Upstream push out minor point releases for bug fixes (MRE will be applied for). Packaging generally in good shape aside from static linking of client binaries (being worked on in Debian). >> libv8 << Availability: In universe for several releases. Rationale: Dependency for MongoDB embedded scripting engine. Security: Lots of CVE's: http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=v8 I suspect that alot of these relate to the use of v8 in Chrome. However as this is a core component of chrome, we can reasonably expect Google to be responsive to security issues in the future. QA: Package works. Regression tests executed during package build. Dependencies: Use gyp for build system. Maintenance: Well maintained in Debian (supports nodejs as well). >> gyp << Availability: In universe. Rationale: Build dependency for libv8 Security: No CVE's found QA: Works from packaging, test suite present but not executed during build. Dependencies: All in main Maintenance: Until recently not that well maintained in Debian; however nodejs maintainer seems to be picking things up now (see version in saucy which refreshed the package considerably). >> snowball << Availability: In universe. Rationale: libstemmer is a build and runtime dependency for mongodb > 2.4 Security: No CVE's found QA: Packaging generally looks good - multi-arched. Unit test suite executed during package build process. Dependencies: All in main. Maintenance: Debian and Ubuntu hold a pre-release snapshot; not much activity in the last 18 months. Background information: libstemmer provides algorithmic stemmer functions for building natural language search functions.
2013-06-04 12:27:40 James Page gyp (Ubuntu): milestone ubuntu-13.08
2013-06-04 12:27:44 James Page libv8 (Ubuntu): milestone ubuntu-13.08
2013-06-04 12:27:50 James Page mongodb (Ubuntu): milestone ubuntu-13.08
2013-06-04 12:27:55 James Page snowball (Ubuntu): milestone ubuntu-13.08
2013-06-04 12:28:01 James Page mongodb (Ubuntu): importance Undecided High
2013-06-04 12:28:04 James Page libv8 (Ubuntu): importance Undecided High
2013-06-04 12:28:07 James Page gyp (Ubuntu): importance Undecided High
2013-06-04 12:28:10 James Page snowball (Ubuntu): importance Undecided High
2013-06-24 16:25:54 James Page bug added subscriber MIR approval team
2013-06-25 19:31:22 Michael Terry mongodb (Ubuntu): assignee Didier Roche (didrocks)
2013-06-28 07:39:12 Didier Roche-Tolomelli mongodb (Ubuntu): assignee Didier Roche (didrocks)
2013-06-28 07:39:33 Didier Roche-Tolomelli libv8 (Ubuntu): assignee Canonical Security Team (canonical-security)
2013-06-28 07:39:47 Didier Roche-Tolomelli bug added subscriber Jamie Strandboge
2013-06-28 11:33:01 Jamie Strandboge libv8 (Ubuntu): assignee Canonical Security Team (canonical-security)
2013-07-01 11:34:30 James Page bug added subscriber Ubuntu Server Team
2013-07-09 15:55:08 Jamie Strandboge libv8 (Ubuntu): status New Won't Fix
2013-07-11 09:56:56 Mitsuya Shibata bug added subscriber Mitsuya Shibata
2013-07-16 12:40:25 Nobuto Murata bug added subscriber Nobuto MURATA
2013-08-17 06:21:07 Julien Danjou bug added subscriber Julien Danjou
2013-08-17 11:52:18 Doug Hellmann bug added subscriber Doug Hellmann
2013-08-28 19:59:21 Launchpad Janitor gyp (Ubuntu): status New Confirmed
2013-08-28 19:59:21 Launchpad Janitor mongodb (Ubuntu): status New Confirmed
2013-08-28 19:59:21 Launchpad Janitor snowball (Ubuntu): status New Confirmed
2013-08-28 23:37:00 Laura Czajkowski bug added subscriber Laura Czajkowski
2013-09-24 16:18:06 Stéphane Graber mongodb (Ubuntu): milestone ubuntu-13.08 ubuntu-13.09
2013-09-24 16:18:08 Stéphane Graber snowball (Ubuntu): milestone ubuntu-13.08 ubuntu-13.09
2013-09-24 16:18:10 Stéphane Graber gyp (Ubuntu): milestone ubuntu-13.08 ubuntu-13.09
2013-10-11 17:11:54 Stéphane Graber mongodb (Ubuntu): milestone ubuntu-13.09 ubuntu-13.10
2013-10-11 17:11:58 Stéphane Graber snowball (Ubuntu): milestone ubuntu-13.09 ubuntu-13.10
2013-10-11 17:12:00 Stéphane Graber gyp (Ubuntu): milestone ubuntu-13.09 ubuntu-13.10
2013-10-21 20:42:01 Stéphane Graber mongodb (Ubuntu): milestone ubuntu-13.10 saucy-updates
2013-10-21 20:42:04 Stéphane Graber snowball (Ubuntu): milestone ubuntu-13.10 saucy-updates
2013-10-21 20:42:06 Stéphane Graber gyp (Ubuntu): milestone ubuntu-13.10 saucy-updates
2014-03-06 09:44:37 James Page mongodb (Ubuntu): status Confirmed Won't Fix
2014-03-06 09:44:41 James Page snowball (Ubuntu): status Confirmed Won't Fix
2014-03-06 09:44:44 James Page gyp (Ubuntu): status Confirmed Won't Fix