Bug#1068085: RM: golang-github-go-git-go-git-fixtures -- RoM; possible vector for security vulnerabilities

2024-03-30 Thread Maytham Alsudany
Control: tags -1 + moreinfo There's ongoing discussion regarding the urgency of go-git-fixtures' removal, and whether such drastic action is necessary. Additionally, it has 2 rdeps in testing that need to be dealt with first. The uploader for the go-git-fixtures package also needs to be

Bug#1068085: RM: golang-github-go-git-go-git-fixtures -- RoM; possible vector for security vulnerabilities

2024-03-30 Thread Maytham Alsudany
Package: ftp.debian.org Severity: normal go-git-fixtures is mainly made up of tgz archives containing bare Git repos, which are decompressed and used in the testing of golang-github-go-git-go-git. In light of the recent xz-utils drama, having binary archives without any easy method of