Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #242796 > unrolled thread

Firefox ESR EOL

Started bypiorunz <piorunz@gmx.com>
First post2021-12-09 11:20 +0100
Last post2021-12-27 15:30 +0100
Articles 20 on this page of 73 — 27 participants

Back to article view | Back to linux.debian.user


Contents

  Firefox ESR EOL piorunz <piorunz@gmx.com> - 2021-12-09 11:20 +0100
    Re: Firefox ESR EOL Georgi Naplatanov <gosho@oles.biz> - 2021-12-09 14:00 +0100
      Re: Firefox ESR EOL piorunz <piorunz@gmx.com> - 2021-12-09 15:20 +0100
        Re: Firefox ESR EOL Tixy <tixy@yxit.co.uk> - 2021-12-09 17:40 +0100
          Re: Firefox ESR EOL Kenneth Parker <sea7kenp@gmail.com> - 2021-12-09 17:50 +0100
          Re: Firefox ESR EOL Roberto C. Sánchez <roberto@debian.org> - 2021-12-09 17:50 +0100
            Re: Firefox ESR EOL Georgi Naplatanov <gosho@oles.biz> - 2021-12-09 18:00 +0100
              Re: Firefox ESR EOL Roberto C. Sánchez <roberto@debian.org> - 2021-12-09 18:30 +0100
                Re: Firefox ESR EOL Georgi Naplatanov <gosho@oles.biz> - 2021-12-09 18:50 +0100
                  Re: Firefox ESR EOL Roberto C. Sánchez <roberto@debian.org> - 2021-12-09 19:30 +0100
                    Re: Firefox ESR EOL Georgi Naplatanov <gosho@oles.biz> - 2021-12-09 20:00 +0100
        Re: Firefox ESR EOL Roberto C. Sánchez <roberto@debian.org> - 2021-12-09 18:30 +0100
          Re: Firefox ESR EOL piorunz <piorunz@gmx.com> - 2021-12-09 18:30 +0100
        Re: Firefox ESR EOL piorunz <piorunz@gmx.com> - 2021-12-09 18:30 +0100
          Re: Firefox ESR EOL "Andrew M.A. Cater" <amacater@einval.com> - 2021-12-09 21:50 +0100
            Re: Firefox ESR EOL Jonathan Dowland <jon+debian-user@dow.land> - 2021-12-09 23:10 +0100
              Re: Firefox ESR EOL piorunz <piorunz@gmx.com> - 2021-12-09 23:20 +0100
                Re: Firefox ESR EOL "Andrew M.A. Cater" <amacater@einval.com> - 2021-12-09 23:30 +0100
                  Re: Firefox ESR EOL Roberto C. Sánchez <roberto@debian.org> - 2021-12-09 23:40 +0100
                Re: Firefox ESR EOL Michael Castellon <castellonmichael@gmail.com> - 2021-12-10 00:00 +0100
                  Re: Firefox ESR EOL Jonathan Dowland <jon+debian-user@dow.land> - 2021-12-10 11:50 +0100
            Re: Firefox ESR EOL Marco Möller <talby@debianlists.mobilxpress.net> - 2021-12-09 23:30 +0100
              Re: Firefox ESR EOL Andrei POPESCU <andreimpopescu@gmail.com> - 2021-12-10 11:00 +0100
                Re: Firefox ESR EOL Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-12-18 21:50 +0100
                  Re: Firefox ESR EOL Anssi Saari <as@sci.fi> - 2021-12-18 23:30 +0100
                    Re: Firefox ESR EOL Dan Ritter <dsr@randomstring.org> - 2021-12-19 00:10 +0100
                    Re: Firefox ESR EOL Rainer Dorsch <ml@bokomoko.de> - 2021-12-19 10:30 +0100
                    Re: Firefox ESR EOL Curt <curty@free.fr> - 2021-12-20 11:00 +0100
                      Re: Firefox ESR EOL Jeremy Ardley <jeremy@ardley.org> - 2021-12-20 11:10 +0100
                        Re: Firefox ESR EOL gene heskett <gheskett@shentel.net> - 2021-12-20 12:50 +0100
                          Re: Firefox ESR EOL Stefan Monnier <monnier@iro.umontreal.ca> - 2021-12-20 15:50 +0100
                            Re: Firefox ESR EOL John Hasler <john@sugarbit.com> - 2021-12-20 17:10 +0100
                            Re: Firefox ESR EOL gene heskett <gheskett@shentel.net> - 2021-12-21 00:00 +0100
                          Re: Firefox ESR EOL Andrei POPESCU <andreimpopescu@gmail.com> - 2021-12-25 12:10 +0100
                            Re: Firefox ESR EOL gene heskett <gheskett@shentel.net> - 2021-12-25 18:40 +0100
                        Re: Firefox ESR EOL Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-12-20 16:40 +0100
                  Re: Firefox ESR EOL David Newman <dnewman@networktest.com> - 2021-12-18 23:30 +0100
                    Re: Firefox ESR EOL Andrei POPESCU <andreimpopescu@gmail.com> - 2021-12-19 09:20 +0100
                      Re: Risc-V [OT: Firefox ESR EOL] Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-12-19 19:50 +0100
                        Re: Risc-V [OT: Firefox ESR EOL] <tomas@tuxteam.de> - 2021-12-20 10:00 +0100
                          Re: Risc-V [OT: Firefox ESR EOL] Andrei POPESCU <andreimpopescu@gmail.com> - 2021-12-25 12:10 +0100
            Re: Firefox ESR EOL Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-12-10 00:10 +0100
            Re: Firefox ESR EOL Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-12-10 00:10 +0100
            Re: Firefox ESR EOL Eric S Fraga <e.fraga@ucl.ac.uk> - 2021-12-10 10:30 +0100
              Re: Firefox ESR EOL Christian Britz <cbritz@t-online.de> - 2021-12-10 11:30 +0100
                Re: Firefox ESR EOL Roberto C. Sánchez <roberto@debian.org> - 2021-12-10 13:30 +0100
                  Re: Firefox ESR EOL Rainer Dorsch <ml@bokomoko.de> - 2021-12-18 12:40 +0100
                    Re: Firefox ESR EOL Georgi Naplatanov <gosho@oles.biz> - 2021-12-18 20:10 +0100
          Re: Firefox ESR EOL Anssi Saari <as@sci.fi> - 2021-12-10 11:50 +0100
    Re: Firefox ESR EOL Christian Britz <cbritz@t-online.de> - 2021-12-09 14:10 +0100
      Re: Firefox ESR EOL Kenneth Parker <sea7kenp@gmail.com> - 2021-12-09 17:20 +0100
      Re: Firefox ESR EOL Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-12-09 19:30 +0100
        Re: Firefox ESR EOL Dan Ritter <dsr@randomstring.org> - 2021-12-09 19:50 +0100
          Re: Firefox ESR EOL Greg Wooledge <greg@wooledge.org> - 2021-12-09 20:00 +0100
          Re: Firefox ESR EOL Christian Britz <cbritz@t-online.de> - 2021-12-10 08:00 +0100
        Re: Firefox ESR EOL Christian Britz <cbritz@t-online.de> - 2021-12-10 07:50 +0100
          Re: Firefox ESR EOL Andrei POPESCU <andreimpopescu@gmail.com> - 2021-12-10 11:30 +0100
    Re: Firefox ESR EOL piorunz <piorunz@gmx.com> - 2021-12-09 18:30 +0100
      Re: Firefox ESR EOL piorunz <piorunz@gmx.com> - 2021-12-09 18:50 +0100
      Re: Firefox ESR EOL Michael Castellon <castellonmichael@gmail.com> - 2021-12-09 22:30 +0100
        Re: Firefox ESR EOL Tixy <tixy@yxit.co.uk> - 2021-12-09 22:50 +0100
        Re: Firefox ESR EOL Nate Bargmann <n0nb@n0nb.us> - 2021-12-10 01:50 +0100
    Re: Firefox ESR EOL Michael Castellon <castellonmichael@gmail.com> - 2021-12-09 18:30 +0100
    [SOLVED] Firefox + Thunderbird upstream solution piorunz <piorunz@gmx.com> - 2021-12-10 15:10 +0100
      Re: [SOLVED] Firefox + Thunderbird upstream solution Michael Castellon <castellonmichael@gmail.com> - 2021-12-10 15:50 +0100
      Re: [SOLVED] Firefox + Thunderbird upstream solution Tixy <tixy@yxit.co.uk> - 2021-12-10 16:40 +0100
        Re: [SOLVED] Firefox + Thunderbird upstream solution piorunz <piorunz@gmx.com> - 2021-12-10 17:00 +0100
          Re: [SOLVED] Firefox + Thunderbird upstream solution Tixy <tixy@yxit.co.uk> - 2021-12-10 17:00 +0100
    Re: Firefox ESR EOL Kushal Kumaran <kushal@locationd.net> - 2021-12-21 02:20 +0100
      Re: Firefox ESR EOL piorunz <piorunz@gmx.com> - 2021-12-26 23:20 +0100
        Re: Firefox ESR EOL Tixy <tixy@yxit.co.uk> - 2021-12-27 09:20 +0100
          Re: Firefox ESR EOL "Andrew M.A. Cater" <amacater@einval.com> - 2021-12-27 09:40 +0100
            Re: Firefox ESR EOL Tixy <tixy@yxit.co.uk> - 2021-12-27 15:30 +0100

Page 3 of 4 — ← Prev page 1 2 [3] 4  Next page →


#243436 — Re: Risc-V [OT: Firefox ESR EOL]

FromAndrei POPESCU <andreimpopescu@gmail.com>
Date2021-12-25 12:10 +0100
SubjectRe: Risc-V [OT: Firefox ESR EOL]
Message-ID<Dyd62-2Up-5@gated-at.bofh.it>
In reply to#243284

[Multipart message — attachments visible in raw view] — view raw

On Lu, 20 dec 21, 09:53:54, tomas@tuxteam.de wrote:
> On Sun, Dec 19, 2021 at 01:44:35PM -0500, Polyna-Maude Racicot-Summerside wrote:
> 
> [...]
> 
> > Would you have some suggestion if I'd like to try out a Risc-V board ?
> 
> Feeding your fave search engine with, e.g. single board computer +"Risc-V"
> yields some hits. A couple of examples:
> 
>   https://liliputing.com/2021/05/nezha-is-a-99-single-board-pc-with-a-risc-v-processor.html
>   https://www.cnx-software.com/2021/04/13/allwinner-d1-linux-risc-v-sbc-processor/
>   https://marketresearchtelecast.com/tried-risc-v-single-board-computer-rvboards-nezha-with-debian-linux/98055/
>   https://www.reddit.com/r/RISCV/comments/kwgcx2/beaglev_the_first_affordable_riscv_computer/
 
https://www.pine64.org/2021/12/15/december-update-a-year-in-review/

> Don't expect laptop-like or desktop-like performance yet -- rather
> embedded-like performance. Those things haven't got the economy of scale
> to justify vast caching architectures and other luxuries. That would
> make them unaffordable. But things might change...

Agreed. This is something to keep an eye on as a potential future 
competitor for ARM, which is starting to challenge x86 in various areas.

Kind regards,
Andrei
-- 
http://wiki.debian.org/FAQsFromDebianUser

[toc] | [prev] | [next] | [standalone]


#242856

FromNicholas Geovanis <nickgeovanis@gmail.com>
Date2021-12-10 00:10 +0100
Message-ID<DsAI1-70n-3@gated-at.bofh.it>
In reply to#242842

[Multipart message — attachments visible in raw view] — view raw

Am I allowed to top-post myself :-)

If we want to make comparisons, why not talk about the BSD flavors? Or
Slackware?
Those are more apples-to-apples comparison.

On Thu, Dec 9, 2021, 5:03 PM Nicholas Geovanis <nickgeovanis@gmail.com>
wrote:

>
>
> On Thu, Dec 9, 2021, 2:44 PM Andrew M.A. Cater <amacater@einval.com>
> wrote:
>
>> On Thu, Dec 09, 2021 at 05:11:05PM +0000, piorunz wrote:
>> >
>> https://www.phoronix.com/scan.php?page=news_item&px=Web-Browser-Packages-Debian
>> >
>> > :(
>> >
>> > --
>> > With kindest regards, Piotr.
>> >
>> > ⢀⣴⠾⠻⢶⣦⠀
>> > ⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
>> > ⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org/
>> > ⠈⠳⣄⠀⠀⠀⠀
>>
>> Yes: not great but also not informed. We do package the latest versions as
>> we can - the latest dependency on Rust is a problem and the point about
>> needing to build toolchains is very valid.
>>
>> Too many comments there are just Debian-bashing with no real
>> understanding.
>>
>> The one thing that would be good would be a backport of the mesa-utils to
>> Bullseye as that would also solve problems with Debian and GUI apps under
>> WSL2 and Windows :)
>>
>
> And there's an even better example than the one I mentioned. But none of
> them are negatives on Debian or its maintainers. Who could have predicted
> the constant churn in linux GUI and graphics and X-Windows since, say, 1996
> when I first started-up twm on a German distro's real MIT X-Windows at
> home. Just like on high end Unix workstations in office and lab.
> That churn is all across Linux, not Debian.
>
> Debian tries to cover every base there. And it simply isn't humanly
> possible. But the maintainers march forward, covering as much ground as
> they can.
>
>
> All the very best, as ever,
>>
>> Andy Cater
>>
>>

[toc] | [prev] | [next] | [standalone]


#242857

FromNicholas Geovanis <nickgeovanis@gmail.com>
Date2021-12-10 00:10 +0100
Message-ID<DsAI1-70n-5@gated-at.bofh.it>
In reply to#242842

[Multipart message — attachments visible in raw view] — view raw

On Thu, Dec 9, 2021, 2:44 PM Andrew M.A. Cater <amacater@einval.com> wrote:

> On Thu, Dec 09, 2021 at 05:11:05PM +0000, piorunz wrote:
> >
> https://www.phoronix.com/scan.php?page=news_item&px=Web-Browser-Packages-Debian
> >
> > :(
> >
> > --
> > With kindest regards, Piotr.
> >
> > ⢀⣴⠾⠻⢶⣦⠀
> > ⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
> > ⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org/
> > ⠈⠳⣄⠀⠀⠀⠀
>
> Yes: not great but also not informed. We do package the latest versions as
> we can - the latest dependency on Rust is a problem and the point about
> needing to build toolchains is very valid.
>
> Too many comments there are just Debian-bashing with no real understanding.
>
> The one thing that would be good would be a backport of the mesa-utils to
> Bullseye as that would also solve problems with Debian and GUI apps under
> WSL2 and Windows :)
>

And there's an even better example than the one I mentioned. But none of
them are negatives on Debian or its maintainers. Who could have predicted
the constant churn in linux GUI and graphics and X-Windows since, say, 1996
when I first started-up twm on a German distro's real MIT X-Windows at
home. Just like on high end Unix workstations in office and lab.
That churn is all across Linux, not Debian.

Debian tries to cover every base there. And it simply isn't humanly
possible. But the maintainers march forward, covering as much ground as
they can.


All the very best, as ever,
>
> Andy Cater
>
>

[toc] | [prev] | [next] | [standalone]


#242880

FromEric S Fraga <e.fraga@ucl.ac.uk>
Date2021-12-10 10:30 +0100
Message-ID<DsKo2-4FE-7@gated-at.bofh.it>
In reply to#242842
On Thursday,  9 Dec 2021 at 20:44, Andrew M.A. Cater wrote:
> Too many comments there are just Debian-bashing with no real understanding.

Indeed, and with absolutely no appreciation for the effort put in by all
of you Debian folk.  Especially in having "stable" *mean* stable!

Thank you all.

-- 
Eric S Fraga with org 9.5.1 in Emacs 29.0.50 on Debian 11.0

[toc] | [prev] | [next] | [standalone]


#242886

FromChristian Britz <cbritz@t-online.de>
Date2021-12-10 11:30 +0100
Message-ID<DsLk7-5ej-21@gated-at.bofh.it>
In reply to#242880

On 2021-12-10 10:25 UTC+0100, Eric S Fraga wrote:
> Indeed, and with absolutely no appreciation for the effort put in by all
> of you Debian folk.  Especially in having "stable" *mean* stable!

I love Debian and I appreciate the work of the developers, but I don't
like stability in the sense of leaving security holes unfixed constantly.

There surely must be a better solution or Debian should put packages
like Chromium, Firefox and Thunderbird on the list of packages without
security support.

[toc] | [prev] | [next] | [standalone]


#242898

FromRoberto C. Sánchez <roberto@debian.org>
Date2021-12-10 13:30 +0100
Message-ID<DsNcd-6mt-3@gated-at.bofh.it>
In reply to#242886
On Fri, Dec 10, 2021 at 11:03:50AM +0100, Christian Britz wrote:
> 
> 
> On 2021-12-10 10:25 UTC+0100, Eric S Fraga wrote:
> > Indeed, and with absolutely no appreciation for the effort put in by all
> > of you Debian folk.  Especially in having "stable" *mean* stable!
> 
Indeed!  For those who would rather have "lastest" instead of "stable",
there are many available solutions, both within and without Debian.

> I love Debian and I appreciate the work of the developers, but I don't
> like stability in the sense of leaving security holes unfixed constantly.
> 
Please note that, as Jonathan pointed out in another message, the
firefox-esr/thunderbird packages specifically have a great deal of
complexity associated with them.  On the whole, security vulnerabilities
in Debian are fixed quite quickly and usually by a group of people made
up mostly of volunteers.

> There surely must be a better solution or Debian should put packages
> like Chromium, Firefox and Thunderbird on the list of packages without
> security support.
> 
That was the case in the past.  In particular, when Mozilla was much
more hostile to downstream distributions concerning things like security
support, branding, and building "modified" packages (e.g., carrying
distribution-specific packages).  The problem with that, of course, is
that Debian buster, the current oldstable distrubtion (still in fairly
active use), was initially released in July 2019.  Firefox ESR 68 was
also released that same month, meaning that the initial buster release
would have contained at best Firefox 60 ESR (initially released May
2018).

If the security team was not making an effort to update to the lastest
ESR release, anyone using buster would have to choose between Firefox 60
ESR from the official repository, a current ESR from an external
provider, or a manual download (as has been discussed in this thread).
None of those seem to be good options.

I remember the "good old days" when the security team didn't support FF
in stable/oldstable.  I remember having no choice but to install from
upstream binary tarballs.  I'd rather not go back to that being the only
choice.

Rather, the fact the security is making the effort says a great deal
about Debian and those who are so committed to it that rather than just
look at this situation (the difficulty of integrating new FF ESR into
Debian stable/oldstable) and "nope", they dedicate themselves to solving
the problems so that Debian users can benefit from a properly supported
web browser.

All the hate in this thread is really very tiresome.  I'm not directing
this specifically to you, Christian, rather speaking of the general tone
of this thread.  Discussing alternatives for users who are concerned
about still being on FF 78 ESR and who would like options for running
the latest ESR is fine.  But bashing on the people who have been working
literally for months on sorting out all of the issues (and there are
many) to bring the latest FF ESR into Debian stable/oldstable is not
productive.  Nor is it productive to point at Debian and other distros
and say things like "they do it, how come Debian can't?"  Each distro
has slightly different objectives, operating frameworks, etc.  Debian's
goals are different from Ubuntu's goals, are different from Fedora's
goals, are different from Mozilla upstream's goals.  Let's just accept
that (or work constructively to adjust the goals to better suit you) and
support the people doing the work.

Regards,

-Roberto

-- 
Roberto C. Sánchez

[toc] | [prev] | [next] | [standalone]


#243233

FromRainer Dorsch <ml@bokomoko.de>
Date2021-12-18 12:40 +0100
Message-ID<DvGee-86P-15@gated-at.bofh.it>
In reply to#242898
Am Freitag, 10. Dezember 2021, 13:25:17 CET schrieb Roberto C. Sánchez:
> [...]
> All the hate in this thread is really very tiresome.  I'm not directing
> this specifically to you, Christian, rather speaking of the general tone
> of this thread.  Discussing alternatives for users who are concerned
> about still being on FF 78 ESR and who would like options for running
> the latest ESR is fine.  But bashing on the people who have been working
> literally for months on sorting out all of the issues (and there are
> many) to bring the latest FF ESR into Debian stable/oldstable is not
> productive.  Nor is it productive to point at Debian and other distros
> and say things like "they do it, how come Debian can't?"  Each distro
> has slightly different objectives, operating frameworks, etc.  Debian's
> goals are different from Ubuntu's goals, are different from Fedora's
> goals, are different from Mozilla upstream's goals.  Let's just accept
> that (or work constructively to adjust the goals to better suit you) and
> support the people doing the work.

Hi Roberto,

thanks and I agree with all you wrote. But also be aware that not all critics 
is bashing and not everybody has the skills and/or time to actively help to 
backport the necessary packages. I do not intend to bash anybody, I understand 
that Debian is based on volunteer work (which is tremendous), and I hope that 
you consider the feedback as constructive.

What I am missing is transparency, but it might be my fault that I just do not 
find the right information. What would help me feeling more comfortable with 
the situation is 

1) a statement which is informing the users through a Debian channel about the 
thread before that appears on Linux Blogs/news channels. Even now I have not 
seen any comment on this topic. I am subscribed to the what I think are the 
relevant Debian channels for Debian users (and some more).

2) an estimate for the ETA. That would it make easier for me to decide if I 
can just wait for the update or if I need to work on another solution myself.


Regards
Rainer


-- 
Rainer Dorsch
http://bokomoko.de/

[toc] | [prev] | [next] | [standalone]


#243243

FromGeorgi Naplatanov <gosho@oles.biz>
Date2021-12-18 20:10 +0100
Message-ID<DvNfH-4oO-7@gated-at.bofh.it>
In reply to#243233
On 12/18/21 13:34, Rainer Dorsch wrote:
> Am Freitag, 10. Dezember 2021, 13:25:17 CET schrieb Roberto C. Sánchez:
>> [...]
>> All the hate in this thread is really very tiresome.  I'm not directing
>> this specifically to you, Christian, rather speaking of the general tone
>> of this thread.  Discussing alternatives for users who are concerned
>> about still being on FF 78 ESR and who would like options for running
>> the latest ESR is fine.  But bashing on the people who have been working
>> literally for months on sorting out all of the issues (and there are
>> many) to bring the latest FF ESR into Debian stable/oldstable is not
>> productive.  Nor is it productive to point at Debian and other distros
>> and say things like "they do it, how come Debian can't?"  Each distro
>> has slightly different objectives, operating frameworks, etc.  Debian's
>> goals are different from Ubuntu's goals, are different from Fedora's
>> goals, are different from Mozilla upstream's goals.  Let's just accept
>> that (or work constructively to adjust the goals to better suit you) and
>> support the people doing the work.
> 
> Hi Roberto,
> 
> thanks and I agree with all you wrote. But also be aware that not all critics 
> is bashing and not everybody has the skills and/or time to actively help to 
> backport the necessary packages. I do not intend to bash anybody, I understand 
> that Debian is based on volunteer work (which is tremendous), and I hope that 
> you consider the feedback as constructive.
> 
> What I am missing is transparency, but it might be my fault that I just do not 
> find the right information. What would help me feeling more comfortable with 
> the situation is 
> 
> 1) a statement which is informing the users through a Debian channel about the 
> thread before that appears on Linux Blogs/news channels. Even now I have not 
> seen any comment on this topic. I am subscribed to the what I think are the 
> relevant Debian channels for Debian users (and some more).
> 
> 2) an estimate for the ETA. That would it make easier for me to decide if I 
> can just wait for the update or if I need to work on another solution myself.
> 


I also think that if Debian project cannot handle with particular
security issue on time then Debian users should be informed.

Kind regards
Georgi

[toc] | [prev] | [next] | [standalone]


#242889

FromAnssi Saari <as@sci.fi>
Date2021-12-10 11:50 +0100
Message-ID<DsLDs-5kE-9@gated-at.bofh.it>
In reply to#242826
piorunz <piorunz@gmx.com> writes:

> https://www.phoronix.com/scan.php?page=news_item&px=Web-Browser-Packages-Debian

They mention the Thunderbird situation as well. Looks like the
Thunderbird Debian package has 22 open security issue and is version
78.14 in stable.

As I've found an AppImage of Librewolf as a reasonable solution to the
browser problem on my Bullseye desktop, I'm left wondering what to do
about Thunderbird? Other than downloading the tarball? Or are these 22
issues too minor to matter? I don't really want to go through all of
them myself.

[toc] | [prev] | [next] | [standalone]


#242800

FromChristian Britz <cbritz@t-online.de>
Date2021-12-09 14:10 +0100
Message-ID<Dsrlo-1mQ-5@gated-at.bofh.it>
In reply to#242796
Security is the reason why I download and install browser and mail
client directly from the vendor, not Debian repositories.

For Chromium the situation is (was) even worse IIRC.

Am 09.12.21 um 11:12 schrieb piorunz:
> Hello,
> 
> I noticed that Debian Stable uses Firefox ESR 78.15.0, which is final
> update of 78 series. All further updates go to Firefox ESR 91, as
> Mozilla page says:
> https://www.mozilla.org/en-US/firefox/78.15.0/releasenotes
> 
> "Version 78.15.0, first offered to ESR channel users on October 5, 2021
> This is the final planned ESR78 release. Eligible users will be
> automatically updated to the ESR91 release on November 2."
> 
> Since 2 November, Firefox 78 is EOL and we all should upgrade. I use
> Debian Bullseye on several of my computers, and they all are on ESR 78.
> 
> Firefox 91 should migrate to Stable as soon as possible, otherwise we
> risk unpatched security vulnerabilities being present in Debian Stable,
> there are several of them already.
> https://security-tracker.debian.org/tracker/source-package/firefox-esr
> 
> Is there any remedy for this?
> 
> --
> With kindest regards, Piotr.
> 
> ⢀⣴⠾⠻⢶⣦⠀
> ⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
> ⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org/
> ⠈⠳⣄⠀⠀⠀⠀
> 

[toc] | [prev] | [next] | [standalone]


#242812

FromKenneth Parker <sea7kenp@gmail.com>
Date2021-12-09 17:20 +0100
Message-ID<Dsujg-36l-15@gated-at.bofh.it>
In reply to#242800

[Multipart message — attachments visible in raw view] — view raw

I am testing Bookworm now, both on xfce and lxde.

On Thu, Dec 9, 2021 at 8:01 AM Christian Britz <cbritz@t-online.de> wrote:

> Security is the reason why I download and install browser and mail
> client directly from the vendor, not Debian repositories.
>
> For Chromium the situation is (was) even worse IIRC.
>

Indeed.   Apt "politely" told me that chromium was "replaced" by
chromium-bsu, an Arcade Shoot-em-up Game!  :-)

 > Am 09.12.21 um 11:12 schrieb piorunz:

<snip>

> Firefox 91 should migrate to Stable as soon as possible, otherwise we
> > risk unpatched security vulnerabilities being present in Debian Stable,
> > there are several of them already.
> > https://security-tracker.debian.org/tracker/source-package/firefox-esr


(Obviously, Bookworm comes before Bullseye in this Process).

To test Firefox 91 in Bookworm, can I use *one* Repository in Unstable, as
an "unofficial Backports"?  (And then only install Firefox 91 from there)?

Thanks in advance,

Kenneth Parker

[toc] | [prev] | [next] | [standalone]


#242829

FromNicholas Geovanis <nickgeovanis@gmail.com>
Date2021-12-09 19:30 +0100
Message-ID<Dswbn-4dC-1@gated-at.bofh.it>
In reply to#242800

[Multipart message — attachments visible in raw view] — view raw

On Thu, Dec 9, 2021, 7:01 AM Christian Britz <cbritz@t-online.de> wrote:

> Security is the reason why I download and install browser and mail
> client directly from the vendor, not Debian repositories.
>

And you may have heard yesterday a young woman on a separate thread advised
NOT to do that. With an audio package IIRC. On general Debian
administration and package management grounds.. No one corrected that
statement later.

For Chromium the situation is (was) even worse IIRC.
>
> Am 09.12.21 um 11:12 schrieb piorunz:
> > Hello,
> >
> > I noticed that Debian Stable uses Firefox ESR 78.15.0, which is final
> > update of 78 series. All further updates go to Firefox ESR 91, as
> > Mozilla page says:
> > https://www.mozilla.org/en-US/firefox/78.15.0/releasenotes
> >
> > "Version 78.15.0, first offered to ESR channel users on October 5, 2021
> > This is the final planned ESR78 release. Eligible users will be
> > automatically updated to the ESR91 release on November 2."
> >
> > Since 2 November, Firefox 78 is EOL and we all should upgrade. I use
> > Debian Bullseye on several of my computers, and they all are on ESR 78.
> >
> > Firefox 91 should migrate to Stable as soon as possible, otherwise we
> > risk unpatched security vulnerabilities being present in Debian Stable,
> > there are several of them already.
> > https://security-tracker.debian.org/tracker/source-package/firefox-esr
> >
> > Is there any remedy for this?
> >
> > --
> > With kindest regards, Piotr.
> >
> > ⢀⣴⠾⠻⢶⣦⠀
> > ⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
> > ⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org/
> > ⠈⠳⣄⠀⠀⠀⠀
> >
>
>

[toc] | [prev] | [next] | [standalone]


#242833

FromDan Ritter <dsr@randomstring.org>
Date2021-12-09 19:50 +0100
Message-ID<DswEq-4n4-5@gated-at.bofh.it>
In reply to#242829
Nicholas Geovanis wrote: 
> On Thu, Dec 9, 2021, 7:01 AM Christian Britz <cbritz@t-online.de> wrote:
> 
> > Security is the reason why I download and install browser and mail
> > client directly from the vendor, not Debian repositories.
> >
> 
> And you may have heard yesterday a young woman on a separate thread advised
> NOT to do that. With an audio package IIRC. On general Debian
> administration and package management grounds.. No one corrected that
> statement later.

Here's the main thing that people like to forget: When you run a Debian
system, you are in charge of it.

You can do anything you like to it.  You get to live with the
consequences.

If you ask for help here, people will recommend that you do
things in a way which minimizes the likelihood that you will
break more things. You don't have to take that advice. But if
you want more useful help here, you should.

It is absolutely okay to create a FrankenDebian with repos from
testing, unstable, Ubuntu Jovial Jackrabbit and a cronjob that
looks for changes to a webpage somewhere in oracle.com and
automatically downloads and installs a new Java Runtime on
alternate Thursdays, then recompiles the kernel with a
bleeding-edge GLIBC-alternative.

But if you want help with that, you should expect to pay someone
for the privilege of dealing with it.

-dsr- 

[toc] | [prev] | [next] | [standalone]


#242835

FromGreg Wooledge <greg@wooledge.org>
Date2021-12-09 20:00 +0100
Message-ID<DswO5-4qq-5@gated-at.bofh.it>
In reply to#242833
On Thu, Dec 09, 2021 at 01:27:56PM -0500, Dan Ritter wrote:
> It is absolutely okay to create a FrankenDebian with repos from
> testing, unstable, Ubuntu Jovial Jackrabbit and a cronjob that
> looks for changes to a webpage somewhere in oracle.com and
> automatically downloads and installs a new Java Runtime on
> alternate Thursdays, then recompiles the kernel with a
> bleeding-edge GLIBC-alternative.
> 
> But if you want help with that, you should expect to pay someone
> for the privilege of dealing with it.

I wouldn't say it's "okay" to do that.  It's possible to do that.  But
it's very far from O.K.

[toc] | [prev] | [next] | [standalone]


#242873

FromChristian Britz <cbritz@t-online.de>
Date2021-12-10 08:00 +0100
Message-ID<DsI2S-39u-5@gated-at.bofh.it>
In reply to#242833
On 2021-12-09 19:27 UTC+0100, Dan Ritter wrote:

> It is absolutely okay to create a FrankenDebian with repos from
> testing, unstable, Ubuntu Jovial Jackrabbit and a cronjob that
> looks for changes to a webpage somewhere in oracle.com and
> automatically downloads and installs a new Java Runtime on
> alternate Thursdays, then recompiles the kernel with a
> bleeding-edge GLIBC-alternative.

You really want to compare that to untarring a mail client to /opt and
linking the executable to /usr/local/bin ? (OK, as a bonus you might
create a .desktop file in /usr/share/applications).

You prefer to live with
https://security-tracker.debian.org/tracker/source-package/thunderbird ?

Regards,
Christian

[toc] | [prev] | [next] | [standalone]


#242872

FromChristian Britz <cbritz@t-online.de>
Date2021-12-10 07:50 +0100
Message-ID<DsHTb-36t-1@gated-at.bofh.it>
In reply to#242829

On 2021-12-09 19:09 UTC+0100, Nicholas Geovanis wrote:
> On Thu, Dec 9, 2021, 7:01 AM Christian Britz <cbritz@t-online.de
> <mailto:cbritz@t-online.de>> wrote:
> 
>     Security is the reason why I download and install browser and mail
>     client directly from the vendor, not Debian repositories.
> 
> 
> And you may have heard yesterday a young woman on a separate thread
> advised NOT to do that. With an audio package IIRC. On general Debian
> administration and package management grounds.. No one corrected that
> statement later.

I read it and I don't care about that questionable absolute statement. I
am using Debian about 20 years now and of course it runs well together
with external software, if you know what you are doing.

I dfinitely won't put my system on risk by using outdated browser and
mail client packages full of security holes.

Best Regards,
Christian

[toc] | [prev] | [next] | [standalone]


#242887

FromAndrei POPESCU <andreimpopescu@gmail.com>
Date2021-12-10 11:30 +0100
Message-ID<DsLk7-5ej-17@gated-at.bofh.it>
In reply to#242872

[Multipart message — attachments visible in raw view] — view raw

On Vi, 10 dec 21, 07:46:34, Christian Britz wrote:
> On 2021-12-09 19:09 UTC+0100, Nicholas Geovanis wrote:
> > On Thu, Dec 9, 2021, 7:01 AM Christian Britz <cbritz@t-online.de
> > <mailto:cbritz@t-online.de>> wrote:
> > 
> >     Security is the reason why I download and install browser and mail
> >     client directly from the vendor, not Debian repositories.
> > 
> > 
> > And you may have heard yesterday a young woman on a separate thread
> > advised NOT to do that. With an audio package IIRC. On general Debian
> > administration and package management grounds.. No one corrected that
> > statement later.
> 
> I read it and I don't care about that questionable absolute statement. I
> am using Debian about 20 years now and of course it runs well together
> with external software, if you know what you are doing.

In my opinion this is the important part ("know what you are doing").

As far as I'm concerned, I'll try to help posters deal with whatever 
FrankenDebian they created as long as they are putting real effort in 
helping themselves first, describing the problem accurately, etc.

Of course, in practice this means most will have solved their own 
problems without needing any assistance from the list ;)

Kind regards,
Andrei
-- 
http://wiki.debian.org/FAQsFromDebianUser

[toc] | [prev] | [next] | [standalone]


#242818

Frompiorunz <piorunz@gmx.com>
Date2021-12-09 18:30 +0100
Message-ID<DsvoZ-3HZ-1@gated-at.bofh.it>
In reply to#242796
On 09/12/2021 17:15, Michael Castellon wrote:
> wget -O firefox.tar 
> "https://download.mozilla.org/?product=firefox-latest&os=linux64 
> <https://download.mozilla.org/?product=firefox-latest&os=linux64>"

Thanks!

Can you generate the same, but for Firefox-ESR?

-- 
With kindest regards, Piotr.

⢀⣴⠾⠻⢶⣦⠀
⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org/
⠈⠳⣄⠀⠀⠀⠀

[toc] | [prev] | [next] | [standalone]


#242828

Frompiorunz <piorunz@gmx.com>
Date2021-12-09 18:50 +0100
Message-ID<DsvIl-3Op-11@gated-at.bofh.it>
In reply to#242818
Got it!!

wget -O firefox.tar.bz2
"https://download.mozilla.org/?product=firefox-esr-latest&os=linux64&lang=en-GB"

tar vxf firefox.tar.bz2

firefox/firefox

You can add switch -P after firefox, it allows you to create new
profile, in case you even want to go back to older ESR. Once updated by
ESR91, it is likely your Fx profile won't work with ESR78 any more. I
recommend backing up .mozilla folder before proceeding.

Sad thing is, /$HOME/firefox/firefox doesn't work with firejail profile
anymore. So I have either vulnerable ESR78 with firejail, or new vanilla
ESR91 without firejail. 😭

--
With kindest regards, Piotr.

⢀⣴⠾⠻⢶⣦⠀
⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org/
⠈⠳⣄⠀⠀⠀⠀

[toc] | [prev] | [next] | [standalone]


#242845

FromMichael Castellon <castellonmichael@gmail.com>
Date2021-12-09 22:30 +0100
Message-ID<Dsz9f-5Y6-3@gated-at.bofh.it>
In reply to#242818

[Multipart message — attachments visible in raw view] — view raw

all versions:
https://ftp.mozilla.org/pub/firefox/releases/

version esr:
wget -O firefox-esr.tar "
https://download.mozilla.org/?product=firefox-esr-latest&os=linux64"

remember, delete cookies, etc:
rm -r ~/.mozilla

Regards.

On Thu, Dec 9, 2021 at 12:28 PM piorunz <piorunz@gmx.com> wrote:

> On 09/12/2021 17:15, Michael Castellon wrote:
> > wget -O firefox.tar
> > "https://download.mozilla.org/?product=firefox-latest&os=linux64
> > <https://download.mozilla.org/?product=firefox-latest&os=linux64>"
>
> Thanks!
>
> Can you generate the same, but for Firefox-ESR?
>
> --
> With kindest regards, Piotr.
>
> ⢀⣴⠾⠻⢶⣦⠀
> ⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
> ⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org/
> ⠈⠳⣄⠀⠀⠀⠀
>

[toc] | [prev] | [next] | [standalone]


Page 3 of 4 — ← Prev page 1 2 [3] 4  Next page →

Back to top | Article view | linux.debian.user


csiph-web