#1107792 apt: hard Depends on security-unsupported package

#1107792#5
Date:
2025-06-14 20:20:20 UTC
From:
To:
$ apt-cache show apt | fgrep Depends:
Depends: base-passwd (>= 3.6.1) | adduser, sqv (>= 1.3.0), […]

However:

$ check-support-status
Limited security support for one or more packages
[…]
* Source:rust-sequoia-sqv
  Details: See https://www.debian.org/releases/trixie/release-notes/issues.en.html#go-and-rust-based-packages
  Affected binary package:
  - sqv (installed version: 1.3.0-3)


This is unsuitable for a release. Either don’t use sqv or make sure
that sqv is security‑ and LTS/ELTS-supported for the release.

#1107792#10
Date:
2025-06-14 20:59:13 UTC
From:
To:
Rest assured this was discussed and approved before the switch happened.
#1107792#25
Date:
2025-06-15 12:38:02 UTC
From:
To:
https://www.debian.org/releases/trixie/release-notes/issues.en.html#go-and-rust-based-packages describes
a generic limitation for Rust and Go-based software. This does not mean that seqv is unsupported, Firefox
is a prominent piece of software which uses Rust to a large degree and does see frequent security updates.

There's no need to have bugs for any package using Go or Rust, so closing it.

Cheers,
        Moritz


Footnotes:
[1] Notably a limitation which applies to every distro, we're just the only one being transparent about it.

#1107792#34
Date:
2025-06-16 00:20:16 UTC
From:
To:
Hi,

might be useful to mark sqv as supported then, if it is,
as an exception to the rule for packages written in these
languages. Otherwise, people using the d-s-s package are
going to get a surprise…

Thanks,
//mirabilos

#1107792#39
Date:
2025-06-16 05:53:21 UTC
From:
To:
indeed. however that´s not soo easy as the codebase doesnt allow that yet.
#1107792#44
Date:
2025-06-16 07:24:30 UTC
From:
To:
Ah, so the marking is automatic, didn’t know that.

Thanks,
//mirabilos