#1111940 RM: golang-gopkg-pg.v5 -- RoQA; not updated since bullseye (same version), has security issues

Package:
ftp.debian.org
Source:
ftp.debian.org
Submitter:
Salvatore Bonaccorso
Date:
2025-08-24 12:25:01 UTC
Severity:
normal
Tags:
#1111940#5
Date:
2025-08-24 07:00:31 UTC
From:
To:
Hi FTP masters,

CC to Sascha and the Debian Go Packaging team, and tagging the issue
moreinfo for having input from SAscha and the Debian Go packaging
team.

golang-gopkg-pg.v5 has not seen updates since 2021 (with a no-change
NMU) from Holger, and only uploads back in 2018.

As the package hat (at least one security) issue open, should
golang-gopkg-pg.v5 (and so as well srcfever) be removed from unstable
(and forky)?

Regards,
Salvatore

#1111940#12
Date:
2025-08-24 07:48:30 UTC
From:
To:
Hi Salvatore,

I see.

Since I'd be sad to see fever go, I would be happy to package a more
recent version of go-pg (e.g. 10.15.0 which should not be affected by
the CVE open as a bug on the current package [1]) and ensure that fever
can build with that, also updating the dependency there. We should then
be fine to remove v5 from unstable and forky once the new version of
go-pg has passed NEW.

Would that be OK with you?

Thanks and best regards
Sascha

[1] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1111939

#1111940#17
Date:
2025-08-24 12:24:12 UTC
From:
To:
Hi Sascha,

yes that soulds like a good plan, so let's defer the removal of
golang-gopkg-pg.v5 for when we have a newer version packaged and
ensured fever can work with it, move to it, and then get
golang-gopkg-pg.v5 removed.

Thank you for the quick response!

So I think we can leave this bug open, with the moreinfo attaached and
remove the moreinfo once fever can move to the new dependency.

Regards,
Salvatore