- Package:
- src:notary
- Source:
- src:notary
- Submitter:
- Mathias Gibbens
- Date:
- 2026-08-24 10:39:03 UTC
- Severity:
- normal
- Tags:
notary's upstream is archived as of July 31, 2025 and no longer maintained[0]. Apparently the successor project is "Notation". I'm filing this bug because notary is going to require a Debian- specific patch to build with the updated golang-github-spf13-viper. It looks like it's been over three years since the last non-team upload. There are still several reverse build dependencies, but I think we ought to seriously consider RMing notary. Mathias [0] -- https://github.com/notaryproject/notary/issues/1709
Hi Mathias, Another important thing is that Notary is a build-dependency for some important packages, in particular docker.io and prometheus and many other go packages are currently marked for auto-removal because of this bug. So we cannot RM notary until those other packages are updates to remove the dependency. Would you agree to lower the severity of the bug and keep it as a to-do?
True, and that makes it much easier to apply patches/fixes without resorting to NMUs through the delayed queue. I would argue this is a perfect time to file Severity: serious bugs for packages with dead upstreams, especially for security-related packages. This gives packages with a build-dependency on it plenty of heads up and time to sort out the dependency issues before we get too close to a release freeze cycle starting. The auto-removal is only from testing, and early in a development cycle, it doesn't really matter. If anything, it might motivate people interested in a package (like docker.io) to spend time working with upstream and/or updating its version in Debian so it will be present in testing in time for the freezes. I won't stand in the way of someone else lowering this bug's severity, but if I need to apply another Debian-specific patch to update a dependency or we go a full year with no real progress I reserve the right to re-raise the severity. :) Mathias
Hi. While going through golang-* packages that fail on https://reproduce.debian.net/all/stats/unstable/ I noticed the 'notary' package and this bug report: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117794 As far as I can tell, there are no longer any reverse dependencies of this package in Debian (see below). Upstream has discussion about deprecating the project: https://github.com/notaryproject/notary/issues/1709 Looks like their main concern was reverse build dependencies, but at least from Debian's point of view, that is no longer an issue. Any objections to finally remove 'notary' from Debian? I believe that leaving packages in 'unstable' but keep them out of testing is a reasonable thing to do, since you never know when a golang-*-dev package may become needed as a build dependency in the future, but I think that for this package, we actively don't want that to happen. /Simon jas@frallan:~$ ssh mirror.ftp-master.debian.org dak rm -Rn notary Will remove the following packages from unstable: golang-github-docker-notary-dev | 0.7.0+git20240416.9d2b3b3+ds1-5 | all notary | 0.7.0+git20240416.9d2b3b3+ds1-5 | source notary | 0.7.0+git20240416.9d2b3b3+ds1-5+b1 | amd64, arm64, armhf, i386, loong64, ppc64el, riscv64, s390x Maintainer: Debian Go Packaging Team <team+pkg-go@tracker.debian.org>------------------- Reason ----------------------------------------------------------------- Checking reverse dependencies... No dependency problem found. jas@frallan:~$
docker.io did vendor notary in 27.5.1+dfsg3-1; not sure if that's still the case. The downside is that this leads to accumulating cruft that bitrots and wastes developer time, for example when running `ratt` encounters a package that fails to build, or when someone running Debian Janitor (or similar) performs pointless cleanup on the package. In the case when a project is explicitly abandoned upstream OR the project is designed to handle security-sensitive actions (both true in the case for notary), I don't think we should keep the package in the archive "just in case". The DFSG team seems to be processing the NEW queue very quickly, so down the road if someone wants to re-introduce a RM'ed package that shouldn't be a large obstacle. Mathias
reassign 1117794 ftp.debian.org severity 1117794 normal affects 1117794 + src:notary retitle 1117794 RM: notary -- ROTeamM; unmaintained and unused user ftp.debian.org@packages.debian.org usertags 1117794 remove thanks The notary package had its last upstream release 8 years ago, it was removed from testing on 2025-11-29 and this bug has been open since October 2025. https://tracker.debian.org/pkg/notary Since then upstream finally archived the project: https://github.com/notaryproject/notary The replacement upstream is: https://github.com/notaryproject/notation Debian provides it as a separate package: https://tracker.debian.org/pkg/golang-github-notaryproject-notation Thus, I don't think this package should be in the archive any more. /Simon
We believe that the bug you reported is now fixed; the following
package(s) have been removed from unstable:
golang-github-docker-notary-dev | 0.7.0+git20240416.9d2b3b3+ds1-5 | all
notary | 0.7.0+git20240416.9d2b3b3+ds1-5 | source
notary | 0.7.0+git20240416.9d2b3b3+ds1-5+b1 | amd64, arm64, armhf, i386, loong64, ppc64el, riscv64, s390x
------------------- Reason -------------------
ROTeamM; unmaintained and unused
----------------------------------------------
Note that the package(s) have simply been removed from the tag
database and may (or may not) still be in the pool; this is not a bug.
The package(s) will be physically removed automatically when no suite
references them (and in the case of source, when no binary references
it). Please also remember that the changes have been done on the
master archive and will not propagate to any mirrors until the next
dinstall run at the earliest.
Packages are usually not removed from testing by hand. Testing tracks
unstable and will automatically remove packages which were removed
from unstable when removing them from testing causes no dependency
problems. The release team can force a removal from testing if it is
really needed, please contact them if this should be the case.
We try to close bugs which have been reported against this package
automatically. But please check all old bugs, if they were closed
correctly or should have been re-assigned to another package.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1117794@bugs.debian.org.
The full log for this bug can be viewed at https://bugs.debian.org/1117794
This message was generated automatically; if you believe that there is
a problem with it please contact the archive administrators by mailing
ftpmaster@ftp-master.debian.org.
Debian distribution maintenance software
pp.
Thorsten Alteholz (the ftpmaster behind the curtain)