#1111940 RM: golang-gopkg-pg.v5 -- RoQA; not updated since bullseye (same version), has security issues #1111940
- Package:
- ftp.debian.org
- Source:
- ftp.debian.org
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2025-08-24 12:25:01 UTC
- Severity:
- normal
- Tags:
Hi FTP masters, CC to Sascha and the Debian Go Packaging team, and tagging the issue moreinfo for having input from SAscha and the Debian Go packaging team. golang-gopkg-pg.v5 has not seen updates since 2021 (with a no-change NMU) from Holger, and only uploads back in 2018. As the package hat (at least one security) issue open, should golang-gopkg-pg.v5 (and so as well srcfever) be removed from unstable (and forky)? Regards, Salvatore
Hi Salvatore, I see. Since I'd be sad to see fever go, I would be happy to package a more recent version of go-pg (e.g. 10.15.0 which should not be affected by the CVE open as a bug on the current package [1]) and ensure that fever can build with that, also updating the dependency there. We should then be fine to remove v5 from unstable and forky once the new version of go-pg has passed NEW. Would that be OK with you? Thanks and best regards Sascha [1] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1111939
Hi Sascha, yes that soulds like a good plan, so let's defer the removal of golang-gopkg-pg.v5 for when we have a newer version packaged and ensured fever can work with it, move to it, and then get golang-gopkg-pg.v5 removed. Thank you for the quick response! So I think we can leave this bug open, with the moreinfo attaached and remove the moreinfo once fever can move to the new dependency. Regards, Salvatore