[bts-link] source package kodi

2021-11-18 Thread debian-bts-link
#
# bts-link upstream status pull for source package kodi
# see http://lists.debian.org/debian-devel-announce/2006/05/msg1.html
# https://bts-link-team.pages.debian.net/bts-link/
#

user debian-bts-l...@lists.debian.org

# remote status report for #999482 (http://bugs.debian.org/999482)
# Bug title: architecture-independent package contains arch-specific lib path
#  * https://github.com/xbmc/xbmc/pull/20506
#  * remote status changed: (?) -> open
usertags 999482 + status-open

thanks



kodi_19.1+dfsg2-2+deb11u1_source.changes ACCEPTED into proposed-updates->stable-new

2021-11-18 Thread Debian FTP Masters
Mapping bullseye to stable.
Mapping stable to proposed-updates.

Accepted:

-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

Format: 1.8
Date: Thu, 04 Nov 2021 09:17:25 +
Source: kodi
Architecture: source
Version: 2:19.1+dfsg2-2+deb11u1
Distribution: bullseye
Urgency: medium
Maintainer: Debian Multimedia Maintainers 
Changed-By: Vasyl Gello 
Changes:
 kodi (2:19.1+dfsg2-2+deb11u1) bullseye; urgency=medium
 .
   * Branch out bullseye
   * Fix buffer overflow in PLS playlists (Closes: CVE-2021-42917)
Checksums-Sha1:
 da8d4289ccf7aaeef44bd887c19598e31fbd9473 5497 kodi_19.1+dfsg2-2+deb11u1.dsc
 7b6b7e998ef4a9da074ce9c5f3ae457b29f7142e 2521220 
kodi_19.1+dfsg2-2+deb11u1.debian.tar.xz
 3dff20fcb12c05dc530233ac6623fc2cbac74a5e 24957 
kodi_19.1+dfsg2-2+deb11u1_amd64.buildinfo
Checksums-Sha256:
 874beb78f6b95f4621e06173217d99d6a0ed8f8838c7475c987800f9d31209e6 5497 
kodi_19.1+dfsg2-2+deb11u1.dsc
 a33f7ace3ce38f00f2f758668c56b6d39483917959b88b301dca170ebfc76f58 2521220 
kodi_19.1+dfsg2-2+deb11u1.debian.tar.xz
 619af9dc3340d12d1578e722dd4f451f850852d25f1368de961f279878b38b0a 24957 
kodi_19.1+dfsg2-2+deb11u1_amd64.buildinfo
Files:
 878c276ad5c41ae1d05730a13998a0cc 5497 video optional 
kodi_19.1+dfsg2-2+deb11u1.dsc
 55f9ab45e9fc63fe2e21cef96f2e5eb5 2521220 video optional 
kodi_19.1+dfsg2-2+deb11u1.debian.tar.xz
 169190fda52fe6de63f4534701e449b7 24957 video optional 
kodi_19.1+dfsg2-2+deb11u1_amd64.buildinfo

-BEGIN PGP SIGNATURE-

iQIzBAEBCgAdFiEEi3hoeGwz5cZMTQpICBa54Yx2K60FAmGWg8IACgkQCBa54Yx2
K62JsA/8D2QsAs057VuBs6fsn1dx7S39C9Bm+X6ZYyS7sgk0VtSxS1SjMSYizv1f
/78BNmt0G70gdc3/vxWZcfqoiYWF3IwpEWiksBo7wXOf9SAhwXG3UAYe2wsU+REu
vYt+QX4MgezzfpHWHKK2bRsdwHXog3JdleFPCXNbqxf1oVJVJWBEfNyrRam7dxJG
6saKhcuL4/3tTviB57Ti2FsOfk8ew96tMeSkANLCmxrwSL+80XOy5ydVao8wcvDW
MimlOFA4th3j+uvd3J4bBkRTyrbaFgL8j4QeiCR6g/+ElqBWDj9itWREBGFfYXM9
gjgzXWgxzoElRn4HKa0xwmg/hHC3+ItgI8RinOTD89HwGB6MDqjPDoOmP5V0brK2
cfsY2j1jV2NUr0laAB4amwjuXBKakBnRcxSha4uS979NZyGmqbvYaPd8PIHR8/xx
AnWPXWX31A4fOOT58XBnvrKjFt0czsgCXpOoFkvtZ52f8tGwQt+OVhhm1AdEa4GT
J45D6TyhNc1tg+uC3pafGJ0lBbbtPuIHnhgReD93KohRCnSFZdZNYvE5OK2k0NQ0
VVw7Uq8/ENnDm7W2nVfAHP8Zc1R86hxvVz+WMKUg1dBIaoiJo7ZRU7RsE/1OLyWY
XSAK9BIHuwsq3FK+cPGjwXWXaFXt+f8A8fpxQsUtKAORR88XcFk=
=UnCc
-END PGP SIGNATURE-


Thank you for your contribution to Debian.



Processing of kodi_19.1+dfsg2-2+deb11u1_source.changes

2021-11-18 Thread Debian FTP Masters
kodi_19.1+dfsg2-2+deb11u1_source.changes uploaded successfully to localhost
along with the files:
  kodi_19.1+dfsg2-2+deb11u1.dsc
  kodi_19.1+dfsg2-2+deb11u1.debian.tar.xz
  kodi_19.1+dfsg2-2+deb11u1_amd64.buildinfo

Greetings,

Your Debian queue daemon (running on host usper.debian.org)



Bug#1000113: kodi: depends on obsolete pcre3 library

2021-11-18 Thread Matthew Vernon
Source: kodi
Severity: important
User: matthew-pcre...@debian.org
Usertags: obsolete-pcre3

Dear maintainer,

Your package still depends on the old, obsolete PCRE3[0] libraries
(i.e. libpcre3-dev). This has been end of life for a while now, and
upstream do not intend to fix any further bugs in it. Accordingly, I
would like to remove the pcre3 libraries from Debian, preferably in
time for the release of Bookworm.

The newer PCRE2 library was first released in 2015, and has been in
Debian since stretch. Upstream's documentation for PCRE2 is available
here: https://pcre.org/current/doc/html/

Many large projects that use PCRE have made the switch now (e.g. git,
php); it does involve some work, but we are now at the stage where
PCRE3 should not be used, particularly if it might ever be exposed to
untrusted input.

This mass bug filing was discussed on debian-devel@ in
https://lists.debian.org/debian-devel/2021/11/msg00176.html

Regards,

Matthew [0] Historical reasons mean that old PCRE is packaged as
pcre3 in Debian 



Bug#1000009: opencollada: depends on obsolete pcre3 library

2021-11-18 Thread Matthew Vernon
Source: opencollada
Severity: important
User: matthew-pcre...@debian.org
Usertags: obsolete-pcre3

Dear maintainer,

Your package still depends on the old, obsolete PCRE3[0] libraries
(i.e. libpcre3-dev). This has been end of life for a while now, and
upstream do not intend to fix any further bugs in it. Accordingly, I
would like to remove the pcre3 libraries from Debian, preferably in
time for the release of Bookworm.

The newer PCRE2 library was first released in 2015, and has been in
Debian since stretch. Upstream's documentation for PCRE2 is available
here: https://pcre.org/current/doc/html/

Many large projects that use PCRE have made the switch now (e.g. git,
php); it does involve some work, but we are now at the stage where
PCRE3 should not be used, particularly if it might ever be exposed to
untrusted input.

This mass bug filing was discussed on debian-devel@ in
https://lists.debian.org/debian-devel/2021/11/msg00176.html

Regards,

Matthew [0] Historical reasons mean that old PCRE is packaged as
pcre3 in Debian