Your message dated Wed, 16 Sep 2026 15:20:46 +0000
with message-id <[email protected]>
and subject line Bug#1148024: fixed in qtpass 1.8.1-1
has caused the Debian Bug report #1148024,
regarding qtpass: new upstream release 1.8.1 (security fixes)
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1148024: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1148024
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: qtpass
Version: 1.6.0-1
Severity: wishlist
X-Debbugs-Cc: [email protected]

Hi Philip,

upstream here. QtPass 1.8.1 was released on 2026-09-15; unstable currently
carries 1.6.0 (2026-04-13). Two upstream releases have happened since:

  1.7.0  2026-04-20
  1.8.0  2026-09-13
  1.8.1  2026-09-15

1.8.1 is a security and bug-fix release, which is why I am filing rather than
waiting. The fixes that matter for Debian users:

* Every gpg encrypt call now passes --no-encrypt-to, as pass does: an
  "encrypt-to" line in the user's gpg.conf could silently add a recipient the
  .gpg-id never listed, i.e. secrets encrypted to an unintended key.
* Only launchable http(s) URLs become clickable links in the password pane;
  previously ssh://, ftp:// and URLs with embedded credentials were linkified
  and handed to the desktop's URL handler.
* The key-generation dialog no longer shows the passphrase in clear text in
  the batch template, and an expert-mode template can no longer produce an
  unprotected key by accident.
* The re-encryption backup commit stages tracked files only, so a stray
  plaintext export or editor swap file in the store is no longer committed and
  auto-pushed to a shared remote.
* Single-instance IPC: a stale socket left by a crash no longer disables it
  permanently, the socket is restricted to the owning user, and a launch whose
  forward fails opens a window instead of exiting silently.
* "New folder" wrote a zero-byte .gpg-id, which shadowed the parent recipients   and made every insert in that folder fail; it is now seeded from the parent. * A configured GPG home that no longer exists is ignored with a status message
  instead of making every gpg call fail with "No secret key".
* Windows/WSL only: commands ran through the WSL login shell, so entry paths,
  .gpg-id recipients and commit messages were word-split and $()-expanded.
  Not exploitable on a Debian system, listed for completeness.

Full list: https://github.com/IJHack/QtPass/blob/v1.8.1/CHANGELOG.md
Release:   https://github.com/IJHack/QtPass/releases/tag/v1.8.1

Notes for packaging 1.8.x:

* debian/watch works unchanged: the release carries QtPass-1.8.1.tar.gz and a
  detached QtPass-1.8.1.tar.gz.asc, signed with my key (same as previous
  releases).
* Qt 6 only since 1.8.0; qt6-base-dev, qt6-tools-dev-tools and now
  qt6-svg-dev (SVG icons are loaded through QIcon, so libqt6svg6 at runtime,
  which d/control already has).
* 1.8.1 installs the desktop file, the AppStream metainfo and the hicolor
  icons itself (main/main.pro INSTALLS), and 2.0 will add the man page, so
  parts of debian/install and debian/qtpass.* may become redundant.
* Two of the three patches look obsolete to me:
  - 03-fix-gpg-detection.patch: since 1.8.0 the probe tries gpg2 and falls
    back to gpg (src/qtpasssettings.cpp, initExecutables()), so no patch is
    needed to find /usr/bin/gpg.
  - 01-disable-tests.patch: the suite runs headless. Upstream CI runs
    "make check TESTARGS='--platform offscreen'" on every push; if you would
    rather keep the tests disabled that is of course fine, but they should
    work in a buildd chroot now and would give the package some coverage.
  - 02-make-reproducible.patch: I am taking this one upstream
    (QMAKE_RESOURCE_FLAGS += --format-version 1 in qtpass.pri), so it can be
    dropped from the next upload that includes it.

Given the gpg.conf recipient issue and the .gpg-id one, 1.8.1 (or the relevant
patches) would be worth considering for trixie via stable-updates or
backports, but I will leave that judgement to you.

Happy to help with anything upstream that makes packaging easier; you can
reach me here or at [email protected].

Thanks for maintaining the package.

--
Anne Jan Brouwer
QtPass upstream

--- End Message ---
--- Begin Message ---
Source: qtpass
Source-Version: 1.8.1-1
Done: Philip Rinn <[email protected]>

We believe that the bug you reported is fixed in the latest version of
qtpass, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Philip Rinn <[email protected]> (supplier of updated qtpass package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Wed, 16 Sep 2026 16:23:17 +0200
Source: qtpass
Architecture: source
Version: 1.8.1-1
Distribution: unstable
Urgency: medium
Maintainer: Philip Rinn <[email protected]>
Changed-By: Philip Rinn <[email protected]>
Closes: 1148024
Changes:
 qtpass (1.8.1-1) unstable; urgency=medium
 .
   * New upstream release (closes: #1148024)
     - drop obsolete patches
   * Bump debhelper compat level to 14 (no changes necessary)
Checksums-Sha1:
 5089ad5ef2cf2eace2927536651dbcf8cd662b20 2174 qtpass_1.8.1-1.dsc
 c124b8095dd4deb7150a7fb1144fb1ba5fb267d6 1742892 qtpass_1.8.1.orig.tar.gz
 5111d184a5300a4c4b27d1ee99b098a0d4f0226a 870 qtpass_1.8.1.orig.tar.gz.asc
 cbb5413f96d7937c351687f1686809bf06ecba5e 6936 qtpass_1.8.1-1.debian.tar.xz
 328666551c9d5072feebc2caf879b3405dea1a5e 11389 qtpass_1.8.1-1_amd64.buildinfo
Checksums-Sha256:
 88563c90afe307358d88b8b39582755f019b248f99b34ea43816df1ee576c636 2174 
qtpass_1.8.1-1.dsc
 3d3ab91dd0a0f0922713f2d3f4fd5fad66ec97cc2d944fb9e5ed4dbb9b953e46 1742892 
qtpass_1.8.1.orig.tar.gz
 f3dfb53dca8ab9d832049c5de6410ee58a3815605d48990f95250f2e90a8076a 870 
qtpass_1.8.1.orig.tar.gz.asc
 45bdc2f4be906a55c1c813a02cbdf605f73c3e3a4a13f2fc97a6deba355f911a 6936 
qtpass_1.8.1-1.debian.tar.xz
 91e52a6827f9c4f87b360f1245e07c4f74058dccccf9dd35a77f36cadb081ee9 11389 
qtpass_1.8.1-1_amd64.buildinfo
Files:
 a4ca1334b6afe433054919cc4c11a22a 2174 utils optional qtpass_1.8.1-1.dsc
 183ab3f76c6719fef86f181bd2bc18f5 1742892 utils optional 
qtpass_1.8.1.orig.tar.gz
 416f20cc1b0b1391409f2c7f6952feab 870 utils optional 
qtpass_1.8.1.orig.tar.gz.asc
 3ff5f3fc11341755515571fc46dd0c19 6936 utils optional 
qtpass_1.8.1-1.debian.tar.xz
 82f27d4db0bb9696fe22ac3f02d3edfd 11389 utils optional 
qtpass_1.8.1-1_amd64.buildinfo


-----BEGIN PGP SIGNATURE-----

wsG7BAEBCgBvBYJqqqzmCRDArzjkoibLNUcUAAAAAAAeACBzYWx0QG5vdGF0aW9u
cy5zZXF1b2lhLXBncC5vcmdRpLPh5RiRcxCrd6uCZvoiDJ8JkXTAy3AqsN8nMMFQ
2hYhBAtmNZoTLWKOn0gUlsCvOOSiJss1AADMJw//Ys5ZB+0QYvD18QT8MkUf8ecr
zFzeb0uFGl0oFaxPqlhn3e/oYz2ekqn3t7IUC7Zte5e0rB0/FWMOGtu76fgK4Cya
6Kri/QE/GleasfTLL6olYnMXpBmrsPE6ZT4H0c+6mPWclTc9h77zkHLMug/lAG8h
/3IFedDavX9YnfqgmZUdV/6JcjAbeFqsGlwJ22rHysDpUAVoGGcz4sad+W9dVfcp
4fO9PII3i1NlMfrzUOtDWn13a/2coKQ5dDHTBuBrO4wxX/TSEq3HKMbMdzlaVlMz
2AI+5Sc4g7leMnasj7Dp1hjKUjLmcLdGI6rDoSl7W/nMmCcsmqGjdpGBqmlKdK0R
MD22Bc4fe2XweiQ8zKPIJt6CCTzv86kbNrGkFArjVKZDI3jUSzUqYDMk2G9UzBEP
9SRG7MFGojiTLsan6TXWcTlNqNb8e+bUmbm4Wd2v98A2uWPoWto9LEouR2mwUK8G
CCb+J8c5vN5K2jQFAIAnU7wSLrv2CczXlnAsIuOBHEZ1Izt4bBn3XN8TBU8ESLxS
vKKvR8ayG2IpLiHffiNjuPG34/8ad6/rM1e7LPiFBJu1JiJSTpEZ9ct3dRgy7lKX
wCoepzLpdw7UxfGlyUQCGmgj5sTowxrzcmhAr5b45BUTky/AdYOncnYCvx/SJ6ka
ETwg5nLU44ky45eRTI4=
=O4fa
-----END PGP SIGNATURE-----

Attachment: pgpze6HDleqGn.pgp
Description: PGP signature


--- End Message ---

Reply via email to