- Package:
- src:chktex
- Source:
- chktex
- Submitter:
- Matthew Vernon
- Date:
- 2022-06-20 18:21:03 UTC
- Severity:
- important
Dear maintainer, Your package still depends on the old, obsolete PCRE3[0] libraries (i.e. libpcre3-dev). This has been end of life for a while now, and upstream do not intend to fix any further bugs in it. Accordingly, I would like to remove the pcre3 libraries from Debian, preferably in time for the release of Bookworm. The newer PCRE2 library was first released in 2015, and has been in Debian since stretch. Upstream's documentation for PCRE2 is available here: https://pcre.org/current/doc/html/ Many large projects that use PCRE have made the switch now (e.g. git, php); it does involve some work, but we are now at the stage where PCRE3 should not be used, particularly if it might ever be exposed to untrusted input. This mass bug filing was discussed on debian-devel@ in https://lists.debian.org/debian-devel/2021/11/msg00176.html Regards, Matthew [0] Historical reasons mean that old PCRE is packaged as pcre3 in Debian
We believe that the bug you reported is fixed in the latest version of
chktex, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1000070@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thorsten Alteholz <debian@alteholz.de> (supplier of updated chktex package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 19 Jun 2022 22:40:03 +0200
Source: chktex
Architecture: source
Version: 1.7.6-5
Distribution: unstable
Urgency: medium
Maintainer: Thorsten Alteholz <debian@alteholz.de>
Changed-By: Thorsten Alteholz <debian@alteholz.de>
Closes: 995650 1000070
Changes:
chktex (1.7.6-5) unstable; urgency=medium
.
* depend on PCRE2 instead of PCRE3 (Closes: #1000070)
* debian/control: bump standard to 4.6.1 (no changes)
* debian/control: use dh13
* debian/control: add Rules-Requires-Root: no
* debian/rules: move to dh
* debian/rules: make it reproducible (Closes: #995650)
Thanks to Vagrant Cascadian for the patch
Checksums-Sha1:
24bc6593d9d40433435ce21b6766ea62b8df4fb3 2064 chktex_1.7.6-5.dsc
08316be4888af58e285a4a933114cd6fd0c29968 44576 chktex_1.7.6-5.debian.tar.xz
0ab9bc2fed02c1a72dc8670951d70c27a18167be 9698 chktex_1.7.6-5_amd64.buildinfo
Checksums-Sha256:
7be49fbbf7be7533b287f9c645d6c809668f5ec1907179e48d9da8578a8cbb2b 2064 chktex_1.7.6-5.dsc
bbc2120a3cdd26f60c5d16f1593034d8d376da60d235ccd947cdaba63567b83f 44576 chktex_1.7.6-5.debian.tar.xz
824d067e704f478a3c685112fd4a737d73a4b56e94ab1c1b66c378bc984011ed 9698 chktex_1.7.6-5_amd64.buildinfo
Files:
a39220cd5df5e539f8f9630ce08c4408 2064 tex optional chktex_1.7.6-5.dsc
da2d39515586b21de94adbc244aa7773 44576 tex optional chktex_1.7.6-5.debian.tar.xz
16a1d3c0e5b96fca0f063473e595208c 9698 tex optional chktex_1.7.6-5_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmKwtGlfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy
MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh
bHRlaG9sei5kZQAKCRCW/KwNOHtYRzC2D/4gTDdj4xUARI3nHHXkLVx/dohOLBZN
p3t6jJLVTx0rEwMzc/gxtlpOUY3PMnLXTk4raLGc/KIbUKsQPke3AGwAqxDipN2u
brX5b1MuI8+dUPjdzyz0nVg4jbq8tqHVtXnvEBuLyVKsXbW9KPGghwnTMaFeF9QJ
ef03YSZjfMH2ibW2XcEVjo3vuOAE3qSmihVzNtfPXGLVu4p3hGMme8qibmq3QcEm
iEUXrkMXIzdiXORYYU5mbYSukjhquIkebBRPI6maAyentliXYEvaxR+eqzW8zwk8
nBkMg7v91O6Y98U4sHT97Eq2BcyCXqgHRUckMa/7oBQM596q6R4aXyFoIDIqJZoC
L4z+1QbYShcIifKvh3ODaQ3/kSza6efp5698XEol2KwQ0GbgPG2yffS2hzPmmkUW
9hr/FttC8k4b1l8MNo8RVav2B1sBN2XC4q36izzozDyhZEGjcLhW8W7GKQyC0Ng2
hX2D2HUDCBoM6y7VrIcy8vImhKIp8NuCukrti+XBYOqBzF+bMqi0YIjdQuMbhgHo
PTydMArPVV01abCAcCNnzmxsv7gcBJ4nrwR1iwgRk1Sag1WpvjESFbW3tds9OgEL
GqLfuVg2H3msWEcXf6KiwHe9YD+qr8QhInqes5Pv1MyTCVbKQB/hZciyK7khVP2W
jHQnVzZXlq3jRw==
=jVzV
-----END PGP SIGNATURE-----