Debian Bug report logs - #886001
node-jquery: please make the build reproducible

version graph

Package: src:node-jquery; Maintainer for src:node-jquery is Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>;

Reported by: Chris Lamb <lamby@debian.org>

Date: Mon, 1 Jan 2018 12:45:04 UTC

Severity: wishlist

Tags: patch

Found in version node-jquery/2.2.4+dfsg-1

Fixed in version node-jquery/2.2.4+dfsg-4

Done: Xavier Guimard <yadd@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, reproducible-bugs@lists.alioth.debian.org, Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>:
Bug#886001; Package src:node-jquery. (Mon, 01 Jan 2018 12:45:07 GMT) (full text, mbox, link).


Acknowledgement sent to Chris Lamb <lamby@debian.org>:
New Bug report received and forwarded. Copy sent to reproducible-bugs@lists.alioth.debian.org, Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>. (Mon, 01 Jan 2018 12:45:07 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Chris Lamb <lamby@debian.org>
To: submit@bugs.debian.org
Subject: node-jquery: please make the build reproducible
Date: Mon, 01 Jan 2018 12:42:34 +0000
[Message part 1 (text/plain, inline)]
Source: node-jquery
Version: 2.2.4+dfsg-1
Severity: wishlist
Tags: patch
User: reproducible-builds@lists.alioth.debian.org
Usertags: timestamps
X-Debbugs-Cc: reproducible-bugs@lists.alioth.debian.org

Hi,

Whilst working on the Reproducible Builds effort [0], we noticed
that node-jquery could not be built reproducibly.

Patch attached. I tried looking at process.env.SOURCE_DATE_EPOCH
instead but that didn't seem to work for some reason.

 [0] https://reproducible-builds.org/


Regards,

-- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      lamby@debian.org / chris-lamb.co.uk
       `-
[node-jquery.diff.txt (text/plain, attachment)]

Message sent on to Chris Lamb <lamby@debian.org>:
Bug#886001. (Tue, 23 Apr 2019 16:18:03 GMT) (full text, mbox, link).


Message #8 received at 886001-submitter@bugs.debian.org (full text, mbox, reply):

From: Xavier Guimard <noreply@salsa.debian.org>
To: 886001-submitter@bugs.debian.org
Subject: Bug #886001 in node-jquery marked as pending
Date: Tue, 23 Apr 2019 16:16:26 +0000
Control: tag -1 pending

Hello,

Bug #886001 in node-jquery reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/js-team/node-jquery/commit/f1c9bd7a1d6d3e13be46a4a846c0ee9768c621fd

------------------------------------------------------------------------
Add patch to make the build reproducible. Thanks to Chris Lamb

Closes: #886001
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/886001



Added tag(s) pending. Request was from Xavier Guimard <noreply@salsa.debian.org> to 886001-submitter@bugs.debian.org. (Tue, 23 Apr 2019 16:18:03 GMT) (full text, mbox, link).


Reply sent to Xavier Guimard <yadd@debian.org>:
You have taken responsibility. (Tue, 23 Apr 2019 16:36:03 GMT) (full text, mbox, link).


Notification sent to Chris Lamb <lamby@debian.org>:
Bug acknowledged by developer. (Tue, 23 Apr 2019 16:36:03 GMT) (full text, mbox, link).


Message #15 received at 886001-close@bugs.debian.org (full text, mbox, reply):

From: Xavier Guimard <yadd@debian.org>
To: 886001-close@bugs.debian.org
Subject: Bug#886001: fixed in node-jquery 2.2.4+dfsg-4
Date: Tue, 23 Apr 2019 16:33:28 +0000
Source: node-jquery
Source-Version: 2.2.4+dfsg-4

We believe that the bug you reported is fixed in the latest version of
node-jquery, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 886001@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Xavier Guimard <yadd@debian.org> (supplier of updated node-jquery package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 23 Apr 2019 18:12:00 +0200
Source: node-jquery
Architecture: source
Version: 2.2.4+dfsg-4
Distribution: unstable
Urgency: medium
Maintainer: Xavier Guimard <yadd@debian.org>
Changed-By: Xavier Guimard <yadd@debian.org>
Closes: 886001 927466
Changes:
 node-jquery (2.2.4+dfsg-4) unstable; urgency=medium
 .
   * Team upload
   * Add upstream/metadata
   * Add homepage
   * Upgrade links to https
   * Fix prototype pollution vulnerability (Closes: #927466, CVE-2019-11358)
   * Add patch to make the build reproducible. Thanks to Chris Lamb
     (Closes: #886001)
Checksums-Sha1: 
 644d03d646809efc0368c33196eda27a11e26d66 2187 node-jquery_2.2.4+dfsg-4.dsc
 8e69baf8d8f90cfee834f23abaee4b602746995c 4252 node-jquery_2.2.4+dfsg-4.debian.tar.xz
Checksums-Sha256: 
 fb768867f23ee0aeac915c5d252e653ec5442974aeb19a2ee887e11e2a843d35 2187 node-jquery_2.2.4+dfsg-4.dsc
 8f32c1cd125782d6fd244ccbd251ab82223cc90c13c29110582e65f750b18cfa 4252 node-jquery_2.2.4+dfsg-4.debian.tar.xz
Files: 
 53ab63b92d72afada3605b42393f8ca2 2187 javascript optional node-jquery_2.2.4+dfsg-4.dsc
 dc9c7caa548fcc3230c5f5f72c320c15 4252 javascript optional node-jquery_2.2.4+dfsg-4.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAly/OgsACgkQ9tdMp8mZ
7uksPA//fT7f4e6pG0bz2PbzYThJMmR/8xS5JKs+8/gzCaGtNKIWRrfwR1ifweID
Hc/myPYpg9Al5n3IFD4c38cTVDHrKHg1KXjQYJMammUmPQ4MgorEvgRDi7cBj///
onj2Ju88kxCgBU5fhu2L5Si6pXGJUtDB/Bi0N0S/S1hgoER7vtXYngJrSQ/Qamx2
jGzhL8/V33Kpi3WOAvrWXHonrzgihOdRHXwrgJcFEtwArtbvk9HKY/ieSOY7UGBh
Jf+8YQJQFkE0AmV7lxLQQ2njGdNhWzTUmfmCvuW9UvcV+OU9SzRFoS4blXrWyrhq
QKYfm9/C5oLkJQM6+zY9DZNF/32SYWukF3ooMNDNgdtwoY+1hoBPnUbZ3gR3qx6T
7daJf/LVms7vYu+mom+8099buL1i5NfaSr/Zgl0y/O9LrsHptpiO8qzjrGRG3bQE
3TNRZ6J5VHXOIB4rZ4Ug79cVFZCXfu3WDag5qtVqa4FDHcdLn/sTbQSz53M6CjCf
y3c+mky9WUwFhZ6CJ1BoLqG388g6faL2u8qENRny0otD7KWePGB+fZn7vmWjbdfP
yMSyNbSt/oljFf0QF2ST8DwmVZqN2dDdczTxGpaUgDis/CKYK1GpbX04GWZxuL3X
iyOGCfdHogs5zAbP8tJ3DwQ0SapShXiPWJOUXOm6PRu6sPtZJfY=
=c3E0
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Mon, 08 Jul 2019 07:25:45 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed May 17 13:45:44 2023; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.