Re: RFC: Consequences of redesign of .deb signatures

2025-09-03 Thread Guillem Jover
Hi! On Wed, 2025-09-03 at 23:59:05 +0300, Peter Pentchev wrote: > On Wed, Sep 03, 2025 at 09:35:12PM +0200, Philipp Kern wrote: > > On 9/2/25 1:55 PM, Guillem Jover wrote: > > > And IMA has indeed the same exact problem, where I'm also not convinced > > > at all about them for the Debian archive.

Bug#1113901: ITP: golang-github-firebase-firebase-admin-go -- Firebase Admin Go SDK

2025-09-03 Thread Ahmad Khalifa
Package: wnpp Severity: wishlist Owner: Ahmad Khalifa X-Debbugs-CC: debian-devel@lists.debian.org, debian...@lists.debian.org * Package name: golang-github-firebase-firebase-admin-go Version : 4.18.0-1 Upstream Author : Firebase * URL : https://github.com/firebase/fir

Re: RFC: Consequences of redesign of .deb signatures

2025-09-03 Thread Peter Pentchev
On Wed, Sep 03, 2025 at 09:35:12PM +0200, Philipp Kern wrote: > Hey :) > > On 9/2/25 1:55 PM, Guillem Jover wrote: > > To be very honest, I've seen the reproducible and key rotation problems > > to be such a concern that I don't think we'd want to have those in the > > archive. I think embedded si

Bug#1113892: ITP: authelia -- authentication and authorization server

2025-09-03 Thread Philipp Kern
Package: wnpp Severity: wishlist Owner: Philipp Kern * Package name: authelia Version : 4.39.8-1 Upstream Author : Authelia * URL : https://github.com/authelia/authelia * License : Apache-2.0 Programming Lang: Go Description : authentication and authori

Re: RFC: Consequences of redesign of .deb signatures

2025-09-03 Thread Philipp Kern
Hey :) On 9/2/25 1:55 PM, Guillem Jover wrote: To be very honest, I've seen the reproducible and key rotation problems to be such a concern that I don't think we'd want to have those in the archive. I think embedded signatures do make sense if your primary way to transport .debs is off-repos and

Bug#1113886: ITP: sql-tool -- Secure SQL tool for AI agents to interact with databases

2025-09-03 Thread Harsh Dadiya
Package: wnpp Severity: wishlist Owner: Harsh Dadiya X-Debbugs-Cc: debian-devel@lists.debian.org, harshdad...@gmail.com * Package name: sql-tool Version : 0.1.9 Upstream Contact: Harsh Dadiya * URL : https://github.com/Dadiya-Harsh/sql-tool * License : MIT P

Re: Bug#1113864: Replace -fcf-protection=full with -fcf-protection=return

2025-09-03 Thread Marcos Del Sol Vives
El 03/09/2025 a las 17:47, Guillem Jover escribió: > Hi! > > On Wed, 2025-09-03 at 16:24:50 +0200, Marcos Del Sol Vives wrote: >> Package: dpkg-dev >> Version: 1.22.21 >> Priority: wishlist >> X-Debbugs-Cc: debian-devel@lists.debian.org > >> Currently, on amd64 and i386 as of Trixie, packages are

Re: Bug#1113864: Replace -fcf-protection=full with -fcf-protection=return

2025-09-03 Thread Guillem Jover
Hi! On Wed, 2025-09-03 at 16:24:50 +0200, Marcos Del Sol Vives wrote: > Package: dpkg-dev > Version: 1.22.21 > Priority: wishlist > X-Debbugs-Cc: debian-devel@lists.debian.org > Currently, on amd64 and i386 as of Trixie, packages are being built by > default with -fcf-protection=full. This result

Re: why package Signal in Debian? (was Re: Bug#1113746: ITP: node-noop6 -- No operation as a module using an arrow function)

2025-09-03 Thread Sebastian Reichel
Hi, On Tue, Sep 02, 2025 at 11:49:59AM +, Stephan Verbücheln wrote: > To my knowledge, no one has ever successfully packaged signal-desktop. > Even the Flatpak build script just downloads the binaries from > signal.org and unpacks the DEB file. > > https://github.com/flathub/org.signal.Signal

Bug#1113864: Replace -fcf-protection=full with -fcf-protection=return

2025-09-03 Thread Marcos Del Sol Vives
Package: dpkg-dev Version: 1.22.21 Priority: wishlist X-Debbugs-Cc: debian-devel@lists.debian.org Hello everyone. I have been instructed by Helmut Grohne from the technical commitee (https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1113774#126) to open a bug here to ask for a change in the curre

Re: Gerrit and different merge UIs

2025-09-03 Thread Sean Whitton
Hello, On Sat 16 Aug 2025 at 02:08pm -07, Otto Kekäläinen wrote: > Hi, > .. >> fantastic for fire and forget changes to a bunch of packages. You can just >> make an MR and enable automerge, and not only will you be told if the > > Yes, this feature is nice and is enabled by default. If you review

Re: salsa: ita: vlock: repository access

2025-09-03 Thread Soren Stoutner
On Tuesday, September 2, 2025 11:29:39 AM Mountain Standard Time Kirill Rekhov wrote: > Hi, Debian > > I have ITA ticket: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=753662 > > could you give me permissions to the repository > https://salsa.debian.org/debian/vlock > -- > Regards, Kirill Re

Re: deb822 sources.list -> Use the 'Signed-By' field?

2025-09-03 Thread Guillem Jover
Hi! On Tue, 2025-09-02 at 14:01:42 +0200, Roland Clobus wrote: > Just before trixie was released, the warning about the deb822 format > for sources.list was removed, now is the time to implement it > properly for forky. > > Recently a MR was prepared for live-build [1] (the generator of the > liv

Re: debian/watch version 5

2025-09-03 Thread Andrea Pappacoda
Hi, > Il giorno 1 set 2025, alle ore 22:59, Peter B ha > scritto: > > Had a quick look at some of these. > Is a blank line needed after the first line with "Version: 5" in it? > Yes, the version has to live in its own paragraph. See the manpage debian-watch, “Format of the Watch file, versio

Re: Gerrit and different merge UIs

2025-09-03 Thread Sean Whitton
Hello, On Tue 02 Sep 2025 at 10:48am -07, Russ Allbery wrote: > There was some confusion after my original message between automerge and > merge queues (what GitLab calls merge trains), which I didn't bother > clarifying at the time because the thread was already too long. But for > the record I

Re: RFC: Consequences of redesign of .deb signatures

2025-09-03 Thread Guillem Jover
Hi! On Tue, 2025-09-02 at 11:16:56 +0200, Philipp Kern wrote: > On 9/1/25 1:23 PM, Guillem Jover wrote: > > * Make the format extensible to other signature formats or workflows > > (such as x509, secure-boot, IMA, etc., even if there's currently no > > intention to add support for any of

Re: RFC: Consequences of redesign of .deb signatures

2025-09-03 Thread Peter Pentchev
On Mon, Sep 01, 2025 at 01:23:30PM +0200, Guillem Jover wrote: > Hi! Thanks a lot for starting this conversation! > The current support for .deb signatures (as implemented by debsigs > and debsig-verify, which dpkg can be configured to call by disabling > the «no-debsig» configuration option), ha

Re: why package Signal in Debian? (was Re: Bug#1113746: ITP: node-noop6 -- No operation as a module using an arrow function)

2025-09-03 Thread Jérémy Lal
Le mar. 2 sept. 2025 à 23:07, Josh Triplett a écrit : > Jonathan Dowland wrote: > > On Tue Sep 2, 2025 at 3:23 AM BST, Sergio Durigan Junior wrote: > > > This package will be maintained by the Debian Javascript team. It's a > > > requirement for signal-desktop. > > > > I use and value Signal, bu

why package Signal in Debian? (was Re: Bug#1113746: ITP: node-noop6 -- No operation as a module using an arrow function)

2025-09-03 Thread Jonathan Dowland
On Tue Sep 2, 2025 at 3:23 AM BST, Sergio Durigan Junior wrote: This package will be maintained by the Debian Javascript team. It's a requirement for signal-desktop. I use and value Signal, but what's the point of packaging signal-desktop in Debian? Surely the packaged client will perennially

Bug#1113792: ITP: sphinxcontrib-runcmd -- Sphinx "runcmd" extension

2025-09-03 Thread Christian Bayle
Package: wnpp Severity: wishlist Owner: Christian Bayle X-Debbugs-Cc: debian-devel@lists.debian.org * Package name: sphinxcontrib-runcmd Version : 0.2.0 Upstream Contact: Fernando Chorney * URL : https://github.com/invenia/sphinxcontrib-runcmd * License : (MIT

Re: debian/watch version 5

2025-09-03 Thread Peter B
On 01/09/2025 21:09, Lucas Nussbaum wrote: ..snip.. And according to UDD there are a few other that are failing: ..snip Had a quick look at some of these. Is a blank line needed after the first line with "Version: 5" in it? Cheers, Peter

Re: why package Signal in Debian? (was Re: Bug#1113746: ITP: node-noop6 -- No operation as a module using an arrow function)

2025-09-03 Thread Roland Clobus
On 02/09/2025 13:32, Jonathan Dowland wrote: On Tue Sep 2, 2025 at 3:23 AM BST, Sergio Durigan Junior wrote: This package will be maintained by the Debian Javascript team.  It's a requirement for signal-desktop. I use and value Signal, but what's the point of packaging signal-desktop in Debia

Re: debian/watch version 5

2025-09-03 Thread Andrea Pappacoda
On Tue Sep 2, 2025 at 9:14 AM CEST, Marc Haber wrote: It would be nice if uscan would recognize both version= and Version:. It currently gets confused and falls back to more ancient versions, giving misleading error messages, when one accidentally starts a v5 file with "version=5", which is an

Bug#1113736: ITP: bpfilter -- An eBPF-based packet filtering framework

2025-09-03 Thread Sudip Mukherjee
Package: wnpp Severity: wishlist Owner: Sudip Mukherjee X-Debbugs-Cc: debian-devel@lists.debian.org, sudipm.mukher...@gmail.com * Package name: bpfilter Version : 0.5.2 Upstream Contact: Many * URL : https://github.com/facebook/bpfilter/ * License : GPL Progr