Comment 5 for bug 2013402

Revision history for this message
William Desportes (williamdes) wrote :

Hi Athos,

> While a single debdiff will suffice here, could we split this in multiple bugs? Then if each changelog entry can refer to a different LP bug. This should make it easier for the SRU team to review this one (each of the bugs should be filled with an SRU template). We can use LP: #1975892 for the minimal version one.

Okay, so I extract the bugs and keep the debdiff on this one ?
Not all entries have LP bugs to close, is that something problematic ?

> Finally, we should make sure all these issues are also addressed in the Ubuntu development version as well (lunar) before we can SRU them. While we are in a freeze, we still have time to upload these to lunar since they are all bug fixes.

Lunar has most of the fixes: https://launchpad.net/ubuntu/+source/phpmyadmin/4:5.2.1+dfsg-1
The CVE is referenced as "PMASA-2023-1" in d/changelog

Since Debian is in freeze, I can not upload new stuff to unstable. Should I wait to make a new SRU for the "libapache2-mod-php" change ?
It's already applied on the package phpsysinfo. And works as expected.

Please let me know more in detail what to do, this is my first SRU.