Bug#1131028: trixie-pu: package golang-github-tillitis-tkeyclient/1.3.0-1~deb13u1 (pre-approval)

Simon Josefsson <[email protected]>
Newsgroups gmane.linux.debian.devel.release
Message-ID <874ii3p5qh.fsf__37624.1811130726$1783937125$gmane$org@josefsson.org>
I looked into making a proper debdiff now, and found a problem.

Upgrading golang-github-tillitis-tkeyclient from 1.1.0-2 (trixie) to new
upstream 1.3.1 depends on a newer version of
golang-github-ccoveille-go-safecast.  Trixie has version 1.6.0-1, but at
least the upstream v2.0.0 is required (already in testing).

We COULD back-port golang-github-ccoveille-go-safecast too, but when
looking into that I realized that upgrading
golang-github-ccoveille-go-safecast from 1.6.x to 2.0.x breaks reverse
builds of not only golang-github-tillitis-tkeyclient (which is expected
and part of the plan) but another unrelated package in trixie:
golang-github-smallstep-certificates-dev.

I stopped looking there, we could back-port
golang-github-smallstep-certificates-dev too.  It only has one reverse
build dependency in trixie: caddy.  I didn't check if caddy in trixie
builds with a more recent golang-github-smallstep-certificates-dev; if
not, back-porting a fix to caddy is required too.

I think this is getting messy.  I'm not convinced this is a reasonable
plan for stable-updates any more.

I'll ask upstream if they could provide a proper back-port of the
security fixes to the golang-github-tillitis-tkeyclient v1.1.0 release
(and the related tkey-ssh-agent v1.0.0 release) without the unrelated
golang-github-ccoveille-go-safecast version bump.

/Simon

Jonathan Wiltshire <[email protected]> writes:

> Control: tag -1 confirmed
>
> Hi,
>
> Please go ahead with the necessary debian/changelog entry added.
>
> Thanks,
signature.asc (application/pgp-signature, 1.2 KB)
-----BEGIN PGP SIGNATURE-----

iQNoBAEWCgMQFiEEo8ychwudMQq61M8vUXIrCP5HRaIFAmpUt7YUHHNpbW9uQGpv
c2Vmc3Nvbi5vcmfCHCYAmDMEXJLOtBYJKwYBBAHaRw8BAQdACIcrZIvhrxDBkK9f
V+QlTmXxo2naObDuGtw58YaxlOu0JVNpbW9uIEpvc2Vmc3NvbiA8c2ltb25Aam9z
ZWZzc29uLm9yZz6IlgQTFggAPgIbAwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgBYh
BLHSvRN1vst4TPT4xNc89jjFPAa+BQJp4fWRBQkOa+rdAAoJENc89jjFPAa+hWIA
/1lQvrJeGlQq50lP6tm99D1zDy7J1tQ3ha4x0Jx7rkFTAP9hpUKuTvm6m1fXyiZV
YZlu2+Id/Dq3CIAZvNF+XEr2BLgzBFySz4EWCSsGAQQB2kcPAQEHQOxTCIOaeXAx
I2hIX4HK9bQTpNVei708oNr1Klm8qCGKiPUEGBYIACYCGwIWIQSx0r0Tdb7LeEz0
+MTXPPY4xTwGvgUCaeCW1wUJDmqLVgCBdiAEGRYIAB0WIQSjzJyHC50xCrrUzy9R
cisI/kdFogUCXJLPgQAKCRBRcisI/kdFoqdMAQCgH45aseZgIrwKOvUOA9QfsmeE
8GZHYNuFHmM9FEQS6AD6A4x5aYvoY6lo98pgtw2HPDhmcCXFItjXCrV4A0GmJA4J
ENc89jjFPAa+s7AA+gIIHpBApDpcDj1sKhzDngmpvwQf0VkHme6s+EG7qSgpAQDe
/XMrU0c0Pa3ji85cMqZhvzJOFI/soe662lzL0QY3Bbg4BFySz2oSCisGAQQBl1UB
BQEBB0AxlRumDW6nZY7A+VCfek9VpEx6PJmdJyYPt3lNHMd6HAMBCAeIfgQYFggA
JgIbDBYhBLHSvRN1vst4TPT4xNc89jjFPAa+BQJp4JbXBQkOaottAAoJENc89jjF
PAa+RNUA/2faQO/nFT06E+MlhlQdo/0chlQXC5TZMPTVvVBFwoLOAP9xLJK0ow5E
jTzYJB4K810AL/Iv6PEOAEgA4cPTHVlbCQAKCRBRcisI/kdFom6PAP9SVvkRv0iE
o4GC5VWdX/+1h9DDaRy2VHtDJt/+TN8rkQD/VcEzchaejLXMGJFhhB6V+BorqaCd
V7K1wq5ORg9uBwM=
=zuG/
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.