-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 18 Jun 2026 11:22:44 +0100 Source: xdg-desktop-portal Architecture: source Version: 1.22.1+ds-1 Distribution: unstable Urgency: medium Maintainer: Utopia Maintenance Team <[email protected]> Changed-By: Simon McVittie <[email protected]> Closes: 1091643 1132958 Changes: xdg-desktop-portal (1.22.1+ds-1) unstable; urgency=medium . * New upstream security fix release - Prevent a malicious or compromised sandboxed app from redirecting drag-and-drop and copy/paste data to itself (GHSA-c5cf-79w8-pvfh) - Prevent a malicious or compromised sandboxed app from gaining arbitrary write access to nonexistent files outside the sandbox (GHSA-cm83-2936-gxjm) - Validate all App IDs in the Document Portal to prevent maliciouss applications from providing a crafted App ID which causes the parsing of arbitrary files on the host as GLib.KeyFile (#2023 upstream) - Disable PipeWire's realtime module to prevent deadlocks (#2012 upstream) . xdg-desktop-portal (1.22.0+ds-1) experimental; urgency=medium . * New upstream release - Reports placeholder data for the root of the xdg-documents-portal filesystem, rather than an error (Closes: #1091643) * d/p/debian/allow-no-graphical-session-target.patch: Add patch from Ubuntu to avoid a regression in desktop environments that don't integrate with `systemd --user`. Thanks to Alessandro Astone (LP: #2144855) * d/watch, d/gbp.conf: Follow the 1.22.x branch * Revert "d/control, d/gbp.conf: Branch for experimental" . xdg-desktop-portal (1.21.1+ds-1) experimental; urgency=medium . * New upstream development prerelease - This version fixes a vulnerability in which a malicious or compromised Flatpak app could send any file or directory to the trash, including those outside its sandbox. (GHSA-rqr9-jwwf-wxgj) (Closes: #1132958) * Merge packaging from unstable * Drop patches that were applied upstream * Standards-Version: 4.7.4 (no changes required) * Normalize formatting of packaging (debputy reformat) Checksums-Sha1: 63edb4058138faa621b6ea1ea37d1e98598d6d6c 3316 xdg-desktop-portal_1.22.1+ds-1.dsc e8698fa389c52461419f672a7dfa65a31d7a2e1c 918588 xdg-desktop-portal_1.22.1+ds.orig.tar.xz 2fd7fb8f44a94e08227d85ff783a3047f428a0ec 16664 xdg-desktop-portal_1.22.1+ds-1.debian.tar.xz 1925ec0f0ea642c91ed826b4951dd2a9c0810d97 18961 xdg-desktop-portal_1.22.1+ds-1_source.buildinfo Checksums-Sha256: 467e9d42cdc8f419d357a621d5dea37e43e81e44cb405f3404d7580d0a354a27 3316 xdg-desktop-portal_1.22.1+ds-1.dsc 97169dc09c91b619c554def9158df2a6faec8e614af29f064feceb5c22188a9f 918588 xdg-desktop-portal_1.22.1+ds.orig.tar.xz 4005e07af0d2cb08fd4d8426a597703c912fb158e75c1399bd81d4cbc05fafb1 16664 xdg-desktop-portal_1.22.1+ds-1.debian.tar.xz a222a989e62f089cd760e2e5fd4017a4aba3634e818a7be1b68cdce7b24f1bdc 18961 xdg-desktop-portal_1.22.1+ds-1_source.buildinfo Files: e7f1e970387ec4b1b5d654bdba2a989f 3316 admin optional xdg-desktop-portal_1.22.1+ds-1.dsc 1119061f82e2ae45cf010b9c2ca82e0d 918588 admin optional xdg-desktop-portal_1.22.1+ds.orig.tar.xz ef98409dbb5181b4b7f682e330b74333 16664 admin optional xdg-desktop-portal_1.22.1+ds-1.debian.tar.xz c9650060b555a1062bb7f12b4bbfc317 18961 admin optional xdg-desktop-portal_1.22.1+ds-1_source.buildinfo
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEegc60a5pT6Jb/2LlI1wJnT6zMHYFAmozymQACgkQI1wJnT6z MHa8pA//UbegD2ImKsPVIa64qD1fwlo3eKnZOt/yOk4MkqaB9s3pOsmE2QF0AmNt Uu5tc4jAM/sB2JYYiMT1uYszctjaBkYYOKQ4EQFUW9MqIyXEO7fD2uz8fkF39hVk 3sSG8yB0IfXIzwhjPLETTW7oXbYo1zjyp1T4WUtD+H7FoYizFa77o5PSt8M+vN2q PwMAB+W6xXsVKOXn9yFJXU3m9F2WatT8tLAiqcpI1O4W9wHhjFcK6ih710VFS6q+ H3bX0H8HIRF8YvfXxoLVJ0wB7na/OkqvnpP9/UWNuyUeiK9FfHipk+/8VsRiBIrZ /qw3k7JbdQtr76+AWhNUKbovBWXuyyR7IXKbIZHjRXr00Ofs4tua+GtJRqhtr3oB efsM2TClzfy+SQSDr14XtPTXwC1f6yoW+5fGCYqHA5mDjGVkRovXZAWypYxt7+H6 7BWEf95cpahOTbB+ivq11OkQUq1eqcER9H/MG6BL7aSM7dtyOJsdIkV458IoNY6k g+/4s/4ZexHRKevzUQtxe+ey8/ykhyupZIRJmCQMI4J9Ux7FmPAl2wKNmK+geuGJ TJgmGxJWI4eFsDxyJ/sU4/cVKH/4ZDJjG96oMCenQCnr8pZVPPW3/qro3KH5kuAD W8CxVXq20ah/xYB02n7xTihP5fGUBviUibUEGukunWusLU7x48s= =+OhO -----END PGP SIGNATURE-----
pgpe3aPnpeXzW.pgp
Description: PGP signature

