desync (1.0.4-1) unstable; urgency=medium . * New upstream version 1.0.4 * d/control: drop the autopkgtest-pkg-go testsuite * d/rules: generate the manpage unconditionally * d/rules: trim cmd/ and testdata/ from the -dev package * d/links: drop the directory symlink workaround eodag (4.6.0+ds-1) unstable; urgency=medium . * New upstream release. * debian/patches: - Refresh all patches. flatpak (1.18.1-1) unstable; urgency=high . * New upstream security fix release (Closes: #1144130) - GHSA-fqx6-vh4p-42cg: Fix writing outside installation directory via crafted commit metadata. A malicious or compromised Flatpak repository could write attacker-controlled files outside /var/lib/flatpak as root. - GHSA-qrwq-7qwx-q9rp: Fix local privilege escalation involving revokefs. A malicious local user could write files outside /var/lib/flatpak as root by tampering with OSTree objects after signature verification. - GHSA-8688-9x26-hhxj: Fix a sandbox escape involving directories inside ~/.var/app/APP_ID. A malicious or compromised Flatpak app could write to arbitrary files outside its sandbox. - GHSA-99wv-m8rp-g58x: Fix a sandbox escape involving the ld.so cache. A malicious or compromised Flatpak app could write files with a fixed name and limited control over content outside the sandbox. - GHSA-v2gw-v9h5-9q4x: Fix local privilege escalation involving crafted OCI architecture names. A malicious local user on a system with an OCI remote configured (unusual on non-Fedora systems) could trick the flatpak-system-helper process into writing outside /var/lib/flatpak. - GHSA-w69g-9x8j-7p8f: Fix reading outside sandbox involving crafted extension metadata. A malicious or compromised Flatpak app could find out whether specific files exist outside the sandbox. - GHSA-q4gr-vc25-57m5: Fix anti-downgrade checks for components installed system-wide. A malicious local user with an active local login session could downgrade an app, runtime or extension to an older, known-vulnerable version and use this to attack other local users. - GHSA-8qxj-x646-phcm: Fix writing outside working directory in `flatpak build-init`. A malicious or compromised SDK could write outside the intended working directory when a developer starts using it for a build. - GHSA-jr92-2v97-wgvc: Fix a buffer overflow when installing or updating from a malicious OCI registry, not believed to be practically exploitable on 64-bit systems. - GHSA-r7hp-698j-2h6c: Correct xdg-dbus-proxy rules for receiving selected AT-SPI broadcasts so that GTK accessibility features work as intended. Previously, these accessibility features only worked accidentally as a result of an xdg-dbus-proxy security issue, fixed in 0.1.8. - Numerous non-security-related bug fixes gobgp (4.8.0-1) unstable; urgency=medium . * New upstream release golang-github-charmbracelet-x (0.0~git20251028.0cf22f8+ds-5) unstable; urgency=medium . * Team upload. * Drop d/.gitignore * Drop ${misc:Depends} with compat 14 * Bump debian/* copyright years * Ignore failing TestWcStringWidth/flag (Closes: #1143755) * Simplify 0002-Skip-failing-test.patch * Silence lintian package-has-long-file-name and unused-override * Silence lintian spelling-error-in-patch-description * Rename d/examples for compat 14 golang-github-containers-buildah (1.43.2+ds1-3) unstable; urgency=medium . * Team Upload. * Tighten dependency on golang-golang-x-sys-dev golang-github-containers-buildah (1.43.2+ds1-2) unstable; urgency=medium . * Team Upload. * Backport upstream patch to fix FTBFS with latest x/sys on 32-bit archs * d/gbp.conf: Set debian branch golang-github-containers-image (5.39.2-2) unstable; urgency=medium . * Team upload * d/control: - Update Standards-Version to 4.7.4, drop Priority field - Add missing Build-Depends and Depends * Add patch to switch from cyberphone/json-canonicalization to gowebpki/jcs, needed to support module-aware builds golang-github-terminalstatic-go-xsd-validate (0.1.6-2) unstable; urgency=medium . * Improve Description * Fix FTBFS on 32-bit archs * Drop Depends: ${misc:Depends} for compat 14 golang-github-terminalstatic-go-xsd-validate (0.1.6-1) unstable; urgency=medium . * Initial release (Closes: #1143010) golang-github-urfave-cli (1.22.17-2) unstable; urgency=medium . * Revert "debian/watch: Use version 5 github template" and start using uscan watch file v5 with correct syntax that only detects v1 releases (if one would ever be made now that v2 and v3 have been around for a while) * Bump Debhelper version from 13 to 14 * Stop using `--buildsystem=golang` * Add myself to Uploaders to signal commitment to maintain the package * Apply consistent formatting to packaging files * Drop redundant `Rules-Requires-Root: no` * Update git repository layout to follow DEP-14 * Enable Salsa CI using default filename golang-github-urfave-cli-v3 (3.10.1-1) unstable; urgency=medium . * New upstream release * Enable Salsa CI using default template * Start using uscan watch file v5 * Add myself to Uploaders to signal commitment to maintain the package * Stop using `--builddirectory` * Bump Debhelper version from 13 to 14 * Apply consistent formatting to packaging files * Drop redundant `Rules-Requires-Root: no` * Bump Debian Policy version to 4.7.4 * Update git repository layout to follow DEP-14 * Start using pristine-tar helpdev (0.7.1-7) unstable; urgency=medium . * Adopt the package under the Debian Python Team umbrella (Closes: #1067786). * Fix debian/watch, which had been failing since gitlab.com moved /tags to /-/tags: uscan concatenated the original and redirected bases into a pattern that matched nothing, and the archive links are now HTML-escaped JSON in a data attribute rather than plain hrefs. Switched to mode=git, which depends on neither. * Add a manual page for helpdev(1). * Add debian/salsa-ci.yml. * Bump Standards-Version to 4.7.4 and debhelper-compat to 14. * Drop the redundant Priority: optional field. kicad-footprints (10.0.5-1) unstable; urgency=medium . * [604fac6] New upstream version 10.0.5 kicad-symbols (10.0.5-1) unstable; urgency=medium . * [469a58a] New upstream version 10.0.5 kwayland (4:6.7.4-1) unstable; urgency=medium . [ Aurélien COUDERC ] * New upstream release (6.7.4). * Use DEB_HOST_MULTIARCH for installation paths with arch triplet. libcrypt-ciphersaber-perl (1.01-3) unstable; urgency=medium . * Maintain in Debian Perl team * Rename source package to follow Perl team policy * Add Homepage Closes: #1142747 * d/watch: version=5 * d/copyright: DEP5 * cme fix dpkg-control * Bump debhelper from deprecated 9 to 14. * Trim trailing whitespace. * Set debhelper-compat version in Build-Depends. * d/control: Use Build-Depends-Indep + nocheck profile * Section: s/interpreters/perl/ * Depends: libscalar-list-utils-perl libnet-cidr-set-perl (0.23-1) unstable; urgency=medium . * New upstream version 0.23. libpsl (0.23.2-1) unstable; urgency=medium . * New upstream version 0.23.2 octave-datatypes (1.3.2-1) unstable; urgency=medium . * New upstream version 1.3.2 * d/copyright: Reflect upstream changes org-roam (2.3.1-2) unstable; urgency=medium . * Team upload. * Declare required dependency: Org-roam does not function without emacsql-sqlite.el, but elpa-org-roam does not declare a dependency on a package that contains it. This library became part of elpa-emacsql in its 4.3.6-2 release, and so elpa-org-roam must declare a minimum dependency on this version. The failure to declare correct dependencies and to actually install an test org-roam resulted in #1144053. * Also migrate the elpa-emacsql-sqlite build-dep (and autopkgtest dep) to elpa-emacsql at this time, because elpa-emacsql-sqlite has become a dummy transitional package. plasma-activities (6.7.4-1) unstable; urgency=medium . [ Aurélien COUDERC ] * New upstream release (6.7.4). * Use DEB_HOST_MULTIARCH for installation paths with arch triplet. plasma-activities-stats (6.7.4-1) unstable; urgency=medium . [ Aurélien COUDERC ] * New upstream release (6.7.4). * Use DEB_HOST_MULTIARCH for installation paths with arch triplet. python-aiokef (0.2.17-2) unstable; urgency=medium . * Team Upload * Fix nocheck build profile (Closes: #1144122) * Rewrite d/rules with newer & shorter syntax * Protect call to sphinx-build in a if-block python-aiokef (0.2.17-1) unstable; urgency=medium . * Initial release. (Closes: #1143485) python-arris-tg2492lg (2.2.0-2) unstable; urgency=medium . * Team upload. * Fix FTBFS with nocheck profile (Closes: #1144123) python-django-split-settings (1.3.2-4) unstable; urgency=medium . * Team upload. * Add build-dep on python3-m2r2 python-laspy (2.7.0-2) unstable; urgency=medium . * Team upload. * Add debian/salsa-ci.yml * Add build dep on new python3-m2r2 * Drop "Rules-Requires-Root: no": it is the default now * Remove redundant Priority: optional from source stanza. * Trim trailing whitespace. * Update standards version to 4.7.4, no changes needed. * Add debian/upstream/metadata python-m2r2 (0.3.4-3) unstable; urgency=medium . * Team Upload * Salsa CI: test the nocheck & nodoc profiles * Rewrite d/rules with newer & shorter syntax * Protect sphinx-build call with a if-block * Fix FTBFS with nodoc profile * Fix FTBFS in nocheck profile (Closes: #1144125) rust-colorchoice (1.0.5-1) unstable; urgency=medium . * Team upload. * Package colorchoice 1.0.5 from crates.io using debcargo 2.8.4 rust-console-log (1.1.0-1) unstable; urgency=medium . * Team upload. * Package console_log 1.1.0 from crates.io using debcargo 2.8.4 rust-dtoa (1.0.11-1) unstable; urgency=medium . * Team upload. * Package dtoa 1.0.11 from crates.io using debcargo 2.8.4 * Add relax-deps.patch for criterion. rust-elsa (1.11.2-1) unstable; urgency=medium . * Package elsa 1.11.2 from crates.io using debcargo 2.8.2 rust-equivalent (1.0.2-1) unstable; urgency=medium . * Team upload. * Package equivalent 1.0.2 from crates.io using debcargo 2.8.4 rust-hstr (0+20250621-6) unstable; urgency=medium . * skip autopkgtest par-core all-features: requires either of features rayon or chili but not both rust-hstr (0+20250621-5) unstable; urgency=medium . * update DEP-3 patch headers * tighten crate version resolving during build * (build-)depend on package for crate chili; drop patch 2002_der, obsoleted by Debian package changes * tighten (build-, autopkgtest-)dependencies * use debhelper compatibility level 14 (not 13) * reorganize patch naming and numbering rust-linux-perf-event-reader (0.10.2-1) unstable; urgency=medium . * Team upload. * Package linux-perf-event-reader 0.10.2 from crates.io using debcargo 2.8.4 rust-msvc-demangler (0.11.0-1) unstable; urgency=medium . * Package msvc-demangler 0.11.0 from crates.io using debcargo 2.8.2 rust-protox-parse (0.9.0-2) unstable; urgency=medium . * Package protox-parse 0.9.0 from crates.io using debcargo 2.8.4 * Narrow test disables and fixes * Drop relax on prost rust-value-bag (1.13.2-1) unstable; urgency=medium . * Team upload. * Package value-bag 1.13.2 from crates.io using debcargo 2.8.4 * Drop several patches in favor of remove_features and filter_targets. * Add relax-deps.patch to relax dependencies. rust-value-bag-serde1 (1.13.2-1) unstable; urgency=medium . * Team upload. * Package value-bag-serde1 1.13.2 from crates.io using debcargo 2.8.4 rust-value-bag-sval2 (1.13.2-1) unstable; urgency=medium . * Team upload. * Package value-bag-sval2 1.13.2 from crates.io using debcargo 2.8.4 * Drop disable-sval-test.diff, sval-test is now in the archive. rust-versionize-derive (0.1.6-1) unstable; urgency=medium . * Team upload. * Package versionize_derive 0.1.6 from crates.io using debcargo 2.8.4 rust-wmidi (4.0.11-1) unstable; urgency=medium . * Team upload. * Package wmidi 4.0.11 from crates.io using debcargo 2.8.4 * Add relax-deps.patch for criterion. utf8-locale (1.1.2-1) unstable; urgency=medium . * New upstream release: - drop the python-hatch-requirements-txt build dependency * Drop the u8loc binary package; that is built from rust-u8loc now. * Drop the libutf8-locale0 library package; nothing ever used it apart from the u8loc executable. * Salsa CI: drop the build-all and build-any jobs for a single package. REMOVED: ciphersaber 1.01-2.2