Bug#1131028: trixie-pu: package golang-github-tillitis-tkeyclient/1.3.0-1~deb13u1 (pre-approval)
Simon Josefsson <[email protected]>
| Newsgroups | gmane.linux.debian.devel.release |
|---|---|
| Message-ID | <874ii3p5qh.fsf__37624.1811130726$1783937125$gmane$org@josefsson.org> |
I looked into making a proper debdiff now, and found a problem. Upgrading golang-github-tillitis-tkeyclient from 1.1.0-2 (trixie) to new upstream 1.3.1 depends on a newer version of golang-github-ccoveille-go-safecast. Trixie has version 1.6.0-1, but at least the upstream v2.0.0 is required (already in testing). We COULD back-port golang-github-ccoveille-go-safecast too, but when looking into that I realized that upgrading golang-github-ccoveille-go-safecast from 1.6.x to 2.0.x breaks reverse builds of not only golang-github-tillitis-tkeyclient (which is expected and part of the plan) but another unrelated package in trixie: golang-github-smallstep-certificates-dev. I stopped looking there, we could back-port golang-github-smallstep-certificates-dev too. It only has one reverse build dependency in trixie: caddy. I didn't check if caddy in trixie builds with a more recent golang-github-smallstep-certificates-dev; if not, back-porting a fix to caddy is required too. I think this is getting messy. I'm not convinced this is a reasonable plan for stable-updates any more. I'll ask upstream if they could provide a proper back-port of the security fixes to the golang-github-tillitis-tkeyclient v1.1.0 release (and the related tkey-ssh-agent v1.0.0 release) without the unrelated golang-github-ccoveille-go-safecast version bump. /Simon Jonathan Wiltshire <[email protected]> writes: > Control: tag -1 confirmed > > Hi, > > Please go ahead with the necessary debian/changelog entry added. > > Thanks,
signature.asc
(application/pgp-signature, 1.2 KB)
-----BEGIN PGP SIGNATURE----- iQNoBAEWCgMQFiEEo8ychwudMQq61M8vUXIrCP5HRaIFAmpUt7YUHHNpbW9uQGpv c2Vmc3Nvbi5vcmfCHCYAmDMEXJLOtBYJKwYBBAHaRw8BAQdACIcrZIvhrxDBkK9f V+QlTmXxo2naObDuGtw58YaxlOu0JVNpbW9uIEpvc2Vmc3NvbiA8c2ltb25Aam9z ZWZzc29uLm9yZz6IlgQTFggAPgIbAwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgBYh BLHSvRN1vst4TPT4xNc89jjFPAa+BQJp4fWRBQkOa+rdAAoJENc89jjFPAa+hWIA /1lQvrJeGlQq50lP6tm99D1zDy7J1tQ3ha4x0Jx7rkFTAP9hpUKuTvm6m1fXyiZV YZlu2+Id/Dq3CIAZvNF+XEr2BLgzBFySz4EWCSsGAQQB2kcPAQEHQOxTCIOaeXAx I2hIX4HK9bQTpNVei708oNr1Klm8qCGKiPUEGBYIACYCGwIWIQSx0r0Tdb7LeEz0 +MTXPPY4xTwGvgUCaeCW1wUJDmqLVgCBdiAEGRYIAB0WIQSjzJyHC50xCrrUzy9R cisI/kdFogUCXJLPgQAKCRBRcisI/kdFoqdMAQCgH45aseZgIrwKOvUOA9QfsmeE 8GZHYNuFHmM9FEQS6AD6A4x5aYvoY6lo98pgtw2HPDhmcCXFItjXCrV4A0GmJA4J ENc89jjFPAa+s7AA+gIIHpBApDpcDj1sKhzDngmpvwQf0VkHme6s+EG7qSgpAQDe /XMrU0c0Pa3ji85cMqZhvzJOFI/soe662lzL0QY3Bbg4BFySz2oSCisGAQQBl1UB BQEBB0AxlRumDW6nZY7A+VCfek9VpEx6PJmdJyYPt3lNHMd6HAMBCAeIfgQYFggA JgIbDBYhBLHSvRN1vst4TPT4xNc89jjFPAa+BQJp4JbXBQkOaottAAoJENc89jjF PAa+RNUA/2faQO/nFT06E+MlhlQdo/0chlQXC5TZMPTVvVBFwoLOAP9xLJK0ow5E jTzYJB4K810AL/Iv6PEOAEgA4cPTHVlbCQAKCRBRcisI/kdFom6PAP9SVvkRv0iE o4GC5VWdX/+1h9DDaRy2VHtDJt/+TN8rkQD/VcEzchaejLXMGJFhhB6V+BorqaCd V7K1wq5ORg9uBwM= =zuG/ -----END PGP SIGNATURE-----