Andrew Lee <[email protected]> writes:

> You can find the draft guide here:
>   https://wiki.debian.org/Teams/DebianGoTeam/ModuleAwareBuilds
>
> I have also updated the GoTeamSprint Phase 2 page to mention this Guide:
>   https://wiki.debian.org/DebConf/26/Sprints/DebianGoTeam/GoModBuilds

I'm having trouble parsing build outputs.  Let's look at this one:

https://salsa.debian.org/go-team/packages/sigstore-go/-/pipelines/1162559

The 'build' job passes and I can confirm dh-lang >= 1.66 is used from
experimental.

However the 'lintian' job still contains these warnings:

P: sigstore-go: binary-contains-insecure-defaultgodebug-settings 
containermaxprocs=0,cryptocustomrand=1,decoratemappings=0,gotestjsonbuildtext=1,httpcookiemaxnum=0,httplaxcontentlength=1,httpmuxgo121=1,httpservecontentkeepheaders=1,multipathtcp=0,panicnil=1,randseednop=0,rsa1024min=0,tlsmlkem=0,tlssecpmlkem=0,tlssha1=1,tracebacklabels=0,updatemaxprocs=0,urlmaxqueryparams=0,urlstrictcolons=0,winreadlinkvolume=0,winsymlink=0,x509negativeserial=1,x509rsacrt=0,x509sha256skid=0,x509sslcertoverrideplatform=0,x509usepolicies=0
 [usr/bin/oci-image-verification]

I was expecting them to go away when rebuilt with dh-golang>=1.66.

How should this be interpreted?  Was the rebuild successful or not?
What if any changes are necessary in this package?

/Simon

Attachment: signature.asc
Description: PGP signature

Reply via email to