[ubuntu/oracular-proposed] curl 8.9.1-2ubuntu1 (Accepted)

Vladimir Petko vladimir.petko at canonical.com
Wed Aug 14 03:59:12 UTC 2024


curl (8.9.1-2ubuntu1) oracular; urgency=medium

  * Merge with Debian unstable (LP: #2076679). Remaining changes:
    - debian/control: Don't build-depend on python3-impacket and stunnel4 on
      i386 so we can drop it (and its dependencies) from the i386 partial port.
      It's only used for the tests, which do not block the build in any case.
    - d/{control,rules}: Do not use gnutls for the curl binary.
    - d/{control,rules}: Drop nghttp3 & ngtcp2 depdendencies of
      libcurl-gnutls to avoid component-mismatch.
  * Drop Changes:
    - d/t/upstream-tests-{gnutls,openssl}: Add workaround to fix
      LP: 2071468. The issue was fixed in dpkg-dev 1.22.11ubuntu1.
  * New Changes:
    - d/rules: Use libssh2-dev as it is in main (LP: #2076865).

curl (8.9.1-2) unstable; urgency=medium

  [ Steve McIntyre ]
  * Improve the patch for the gnutls build. Instead of calling quilt
    during the binary package build, use autotools to do the work we
    need when calling configure etc. Closes: #1077650

  [ Carlos Henrique Lima Melara ]
  * debian/control: bump Standards-Version to 4.7.0, no changes needed.
  * debian/patches/ignore-SIGPIPE-after-init.patch: add new patch from
    upstream. (Closes: #1077854)
  * debian/tests/build-using-libcurl*: add tests to check if libcurl headers
    and pkgconf info are correct.

curl (8.9.1-1) unstable; urgency=medium

  * New upstream version 8.9.1. (Closes: 1077656)
    - fix CVE-2024-7264: ASN.1 date parser overread.
  * debian/patch/build-Divide-mit-[...].patch: refresh patch.

curl (8.9.0-3) unstable; urgency=medium

  * debian/control: make libcurl*-dev packages Depends on -dev packages.
    (Closes: #1077197, #1077190)
  * debian/rules: decrease tests parallelism multiplier.

curl (8.9.0-2) unstable; urgency=medium

  * debian/control: make libcurl*-dev packages Recommends -dev packages.
    (Closes: #1077197, #1077190)

curl (8.9.0-1) unstable; urgency=medium

  [ Samuel Henrique ]
  * debian/curl.NEWS: Update wcurl description.

  [ Carlos Henrique Lima Melara ]
  * New upstream version 8.9.0. (Closes: #1076996)
    - fix CVE-2024-6197: freeing stack buffer in utf8asn1str.
    - fix CVE-2024-6874: macidn punycode buffer overread.
  * debian/copyright: drop copyright from removed file.
  * debian/patches/: drop merged patches and refresh patches against new
    upstream release.
      - docs_makefile_am_make_curl_config_1_install.patch: drop.
      - fix-x509asn1-fallback-to-dotted-OID-representation.patch: drop.
  * debian/gbp.conf: add upstream-branch definition.

curl (8.8.0-4) unstable; urgency=medium

  [ Adrian Bunk ]
  * Revert "Temporarily disable build-time tests on 32-bit non-x86"
  * Don't use python3-impacket on non-Rust architectures that lack
    python-cryptography

  [ Lev Lazinskiy ]
  * Use SALSA_CI_DPKG_BUILDPACKAGE_ARGS in pipeline

  [ Samuel Henrique ]
  * Update wcurl to 2024.07.10

Date: Tue, 13 Aug 2024 09:16:22 +1200
Changed-By: Vladimir Petko <vladimir.petko at canonical.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/curl/8.9.1-2ubuntu1
-------------- next part --------------
Format: 1.8
Date: Tue, 13 Aug 2024 09:16:22 +1200
Source: curl
Built-For-Profiles: noudeb
Architecture: source
Version: 8.9.1-2ubuntu1
Distribution: oracular
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Vladimir Petko <vladimir.petko at canonical.com>
Closes: 1076996 1077190 1077197 1077650 1077656 1077854
Launchpad-Bugs-Fixed: 2076679 2076865
Changes:
 curl (8.9.1-2ubuntu1) oracular; urgency=medium
 .
   * Merge with Debian unstable (LP: #2076679). Remaining changes:
     - debian/control: Don't build-depend on python3-impacket and stunnel4 on
       i386 so we can drop it (and its dependencies) from the i386 partial port.
       It's only used for the tests, which do not block the build in any case.
     - d/{control,rules}: Do not use gnutls for the curl binary.
     - d/{control,rules}: Drop nghttp3 & ngtcp2 depdendencies of
       libcurl-gnutls to avoid component-mismatch.
   * Drop Changes:
     - d/t/upstream-tests-{gnutls,openssl}: Add workaround to fix
       LP: 2071468. The issue was fixed in dpkg-dev 1.22.11ubuntu1.
   * New Changes:
     - d/rules: Use libssh2-dev as it is in main (LP: #2076865).
 .
 curl (8.9.1-2) unstable; urgency=medium
 .
   [ Steve McIntyre ]
   * Improve the patch for the gnutls build. Instead of calling quilt
     during the binary package build, use autotools to do the work we
     need when calling configure etc. Closes: #1077650
 .
   [ Carlos Henrique Lima Melara ]
   * debian/control: bump Standards-Version to 4.7.0, no changes needed.
   * debian/patches/ignore-SIGPIPE-after-init.patch: add new patch from
     upstream. (Closes: #1077854)
   * debian/tests/build-using-libcurl*: add tests to check if libcurl headers
     and pkgconf info are correct.
 .
 curl (8.9.1-1) unstable; urgency=medium
 .
   * New upstream version 8.9.1. (Closes: 1077656)
     - fix CVE-2024-7264: ASN.1 date parser overread.
   * debian/patch/build-Divide-mit-[...].patch: refresh patch.
 .
 curl (8.9.0-3) unstable; urgency=medium
 .
   * debian/control: make libcurl*-dev packages Depends on -dev packages.
     (Closes: #1077197, #1077190)
   * debian/rules: decrease tests parallelism multiplier.
 .
 curl (8.9.0-2) unstable; urgency=medium
 .
   * debian/control: make libcurl*-dev packages Recommends -dev packages.
     (Closes: #1077197, #1077190)
 .
 curl (8.9.0-1) unstable; urgency=medium
 .
   [ Samuel Henrique ]
   * debian/curl.NEWS: Update wcurl description.
 .
   [ Carlos Henrique Lima Melara ]
   * New upstream version 8.9.0. (Closes: #1076996)
     - fix CVE-2024-6197: freeing stack buffer in utf8asn1str.
     - fix CVE-2024-6874: macidn punycode buffer overread.
   * debian/copyright: drop copyright from removed file.
   * debian/patches/: drop merged patches and refresh patches against new
     upstream release.
       - docs_makefile_am_make_curl_config_1_install.patch: drop.
       - fix-x509asn1-fallback-to-dotted-OID-representation.patch: drop.
   * debian/gbp.conf: add upstream-branch definition.
 .
 curl (8.8.0-4) unstable; urgency=medium
 .
   [ Adrian Bunk ]
   * Revert "Temporarily disable build-time tests on 32-bit non-x86"
   * Don't use python3-impacket on non-Rust architectures that lack
     python-cryptography
 .
   [ Lev Lazinskiy ]
   * Use SALSA_CI_DPKG_BUILDPACKAGE_ARGS in pipeline
 .
   [ Samuel Henrique ]
   * Update wcurl to 2024.07.10
Checksums-Sha1:
 a76e326c94745192161473d004855bc0e7f29279 3035 curl_8.9.1-2ubuntu1.dsc
 9bcf387f274ae96ad591115d9f9f23700ec76ceb 4200000 curl_8.9.1.orig.tar.gz
 c461be89031623e1198ebe118da2b1b7a38671ed 53768 curl_8.9.1-2ubuntu1.debian.tar.xz
 f09f7ee67bbaceca265c748416276473f64e58de 10580 curl_8.9.1-2ubuntu1_source.buildinfo
Checksums-Sha256:
 6bc961d405986ec58cefdebd75bc42af7264e19d73789aebf7c5301dd3a21f92 3035 curl_8.9.1-2ubuntu1.dsc
 291124a007ee5111997825940b3876b3048f7d31e73e9caa681b80fe48b2dcd5 4200000 curl_8.9.1.orig.tar.gz
 85b48231af642a8995db1f2ab341627212b476cf46b7bc6ca4345e5207396708 53768 curl_8.9.1-2ubuntu1.debian.tar.xz
 c9aa32e78b2404fed44704b0997203504da4b6e275ab4b28908331ab2f1fb96d 10580 curl_8.9.1-2ubuntu1_source.buildinfo
Files:
 c21bae5f0ec345988f59ed54f70ff5fc 3035 web optional curl_8.9.1-2ubuntu1.dsc
 2570f590c998d65d52b93141edb521e1 4200000 web optional curl_8.9.1.orig.tar.gz
 2d110da202daebe86756ae926b04f576 53768 web optional curl_8.9.1-2ubuntu1.debian.tar.xz
 a8ebdfe3624bd7626f30a5452394cf3f 10580 web optional curl_8.9.1-2ubuntu1_source.buildinfo
Original-Maintainer: Debian Curl Maintainers <team+curl at tracker.debian.org>
Vcs-Git: https://git.launchpad.net/~vpa1977/ubuntu/+source/curl
Vcs-Git-Commit: 14cb00fb4d2b13185fbf7609cbf90aec0563f33f
Vcs-Git-Ref: refs/heads/merge-lp2076679


More information about the oracular-changes mailing list