#1117794 notary: Abandoned upstream, should probably RM

#1117794#5
Date:
2025-10-10 23:29:40 UTC
From:
To:
  notary's upstream is archived as of July 31, 2025 and no longer
maintained[0]. Apparently the successor project is "Notation".

  I'm filing this bug because notary is going to require a Debian-
specific patch to build with the updated golang-github-spf13-viper. It
looks like it's been over three years since the last non-team upload.
There are still several reverse build dependencies, but I think we
ought to seriously consider RMing notary.

Mathias

[0] -- https://github.com/notaryproject/notary/issues/1709

#1117794#14
Date:
2025-10-28 20:23:16 UTC
From:
To:
Hi Mathias,

Another important thing is that Notary is a build-dependency for some important packages, in particular docker.io and prometheus and many other go packages are currently marked for auto-removal because of this bug. So we cannot RM notary until those other packages are updates to remove the dependency.

Would you agree to lower the severity of the bug and keep it as a to-do?

#1117794#19
Date:
2025-11-09 05:15:58 UTC
From:
To:
  True, and that makes it much easier to apply patches/fixes without
resorting to NMUs through the delayed queue.
I would argue this is a perfect time to file Severity: serious bugs for
packages with dead upstreams, especially for security-related packages.
This gives packages with a build-dependency on it plenty of heads up
and time to sort out the dependency issues before we get too close to a
release freeze cycle starting.

  The auto-removal is only from testing, and early in a development
cycle, it doesn't really matter. If anything, it might motivate people
interested in a package (like docker.io) to spend time working with
upstream and/or updating its version in Debian so it will be present in
testing in time for the freezes.

  I won't stand in the way of someone else lowering this bug's
severity, but if I need to apply another Debian-specific patch to
update a dependency or we go a full year with no real progress I
reserve the right to re-raise the severity. :)

Mathias

#1117794#24
Date:
2026-05-04 12:42:46 UTC
From:
To:
Hi.

While going through golang-* packages that fail on
https://reproduce.debian.net/all/stats/unstable/ I noticed the 'notary'
package and this bug report:

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117794

As far as I can tell, there are no longer any reverse dependencies of
this package in Debian (see below).

Upstream has discussion about deprecating the project:

https://github.com/notaryproject/notary/issues/1709

Looks like their main concern was reverse build dependencies, but at
least from Debian's point of view, that is no longer an issue.

Any objections to finally remove 'notary' from Debian?

I believe that leaving packages in 'unstable' but keep them out of
testing is a reasonable thing to do, since you never know when a
golang-*-dev package may become needed as a build dependency in the
future, but I think that for this package, we actively don't want that
to happen.

/Simon

jas@frallan:~$ ssh mirror.ftp-master.debian.org dak rm -Rn notary
Will remove the following packages from unstable:

golang-github-docker-notary-dev | 0.7.0+git20240416.9d2b3b3+ds1-5 | all
    notary | 0.7.0+git20240416.9d2b3b3+ds1-5 | source
    notary | 0.7.0+git20240416.9d2b3b3+ds1-5+b1 | amd64, arm64, armhf, i386, loong64, ppc64el, riscv64, s390x

Maintainer: Debian Go Packaging Team <team+pkg-go@tracker.debian.org>
------------------- Reason -------------------
---------------------------------------------- Checking reverse dependencies... No dependency problem found. jas@frallan:~$
#1117794#29
Date:
2026-05-04 13:44:19 UTC
From:
To:
  docker.io did vendor notary in 27.5.1+dfsg3-1; not sure if that's
still the case.

  The downside is that this leads to accumulating cruft that bitrots
and wastes developer time, for example when running `ratt` encounters a
package that fails to build, or when someone running Debian Janitor (or
similar) performs pointless cleanup on the package.

  In the case when a project is explicitly abandoned upstream OR the
project is designed to handle security-sensitive actions (both true in
the case for notary), I don't think we should keep the package in the
archive "just in case". The DFSG team seems to be processing the NEW
queue very quickly, so down the road if someone wants to re-introduce a
RM'ed package that shouldn't be a large obstacle.

Mathias

#1117794#34
Date:
2026-08-24 07:03:39 UTC
From:
To:
reassign 1117794 ftp.debian.org
severity 1117794 normal
affects 1117794 + src:notary
retitle 1117794 RM: notary -- ROTeamM; unmaintained and unused
user ftp.debian.org@packages.debian.org
usertags 1117794 remove
thanks

The notary package had its last upstream release 8 years ago, it was
removed from testing on 2025-11-29 and this bug has been open since
October 2025.

https://tracker.debian.org/pkg/notary

Since then upstream finally archived the project:

https://github.com/notaryproject/notary

The replacement upstream is:

https://github.com/notaryproject/notation

Debian provides it as a separate package:

https://tracker.debian.org/pkg/golang-github-notaryproject-notation

Thus, I don't think this package should be in the archive any more.

/Simon

#1117794#49
Date:
2026-08-24 10:37:04 UTC
From:
To:
We believe that the bug you reported is now fixed; the following
package(s) have been removed from unstable:

golang-github-docker-notary-dev | 0.7.0+git20240416.9d2b3b3+ds1-5 | all
    notary | 0.7.0+git20240416.9d2b3b3+ds1-5 | source
    notary | 0.7.0+git20240416.9d2b3b3+ds1-5+b1 | amd64, arm64, armhf, i386, loong64, ppc64el, riscv64, s390x
------------------- Reason ------------------- ROTeamM; unmaintained and unused ---------------------------------------------- Note that the package(s) have simply been removed from the tag database and may (or may not) still be in the pool; this is not a bug. The package(s) will be physically removed automatically when no suite references them (and in the case of source, when no binary references it). Please also remember that the changes have been done on the master archive and will not propagate to any mirrors until the next dinstall run at the earliest. Packages are usually not removed from testing by hand. Testing tracks unstable and will automatically remove packages which were removed from unstable when removing them from testing causes no dependency problems. The release team can force a removal from testing if it is really needed, please contact them if this should be the case. We try to close bugs which have been reported against this package automatically. But please check all old bugs, if they were closed correctly or should have been re-assigned to another package. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1117794@bugs.debian.org. The full log for this bug can be viewed at https://bugs.debian.org/1117794 This message was generated automatically; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org. Debian distribution maintenance software pp. Thorsten Alteholz (the ftpmaster behind the curtain)