- Package:
- src:m2crypto
- Source:
- src:m2crypto
- Submitter:
- Bastian Germann
- Date:
- 2026-05-05 14:59:01 UTC
- Severity:
- normal
Upstream writes on the homepage: "NOTE: This library is currently in maintenance mode. We recommend using a more modern alternative such as PyCA/cryptography. Examples of how to migrate can be found in the documentation." I suggest that this should no longer be in forky and am going to file a removal bug as soon as the last reverse dependency has moved to a different library. I have just filed a patch upstream to achieve this.
Dear submitter, as the package m2crypto has just been removed from the Debian archive unstable we hereby close the associated bug reports. We are sorry that we couldn't deal with your issue properly. For details on the removal, please see https://bugs.debian.org/1127821 The version of this package that was in Debian prior to this removal can still be found using https://snapshot.debian.org/. Please note that the changes have been done on the master archive and will not propagate to any mirrors until the next dinstall run at the earliest. This message was generated automatically; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org. Debian distribution maintenance software pp. Thorsten Alteholz (the ftpmaster behind the curtain)
Hi, this is the upstream maintainer of the M2Crypto, I would say that you were a bit hasty in removing M2Crypto from Debian. By saying that M2Crypto is for legacy applications and shouldn’t be used for new projects, I didn’t mean to say it is abandoned and there are no users of it. Just contrary, I am always surprised how many people still use it in their applications, and it would be probably better if they got it through Debian with updates and security fixes, then they would have it unmaintained build from my tarball. I have been maintaining M2Crypto since 2014 and as I have described to some requests on our email list [1], I don’t plan to stop maintaining it anytime soon. Does [2] convey more hopefull message? Please, reconsider the removal of the package from Debian. Best, Matěj Cepl [1] https://lists.sr.ht/~mcepl/m2crypto/<CAHVK=8ofcDiJXzpcBCPZitgXuO0YULR6UOZtp8rk7vbtzV4zWg@mail.gmail.com> [2] https://gitea.com/mcepl/m2crypto/pulls/4
Bastian worked on replacing m2crypto usage in Debian, for the next
release (Debian 14 / forky). Thus no users *in* Debian were left
(this however means something different than "no Debian users").
[..]
The removal was completed in March. By now someone would have to
spend time and work to introduce the package anew.
For libraries there is often a tradeoff weighing, and libraries that
have no direct users inside Debian ("leaf libraries") need to have
really dedicated maintainers that want to spend the time and work in
Debian on that library. You can imagine that finding such
maintainers is often not so easy. For security-relevant libraries
the work is of course higher and they should get security updates;
for leaf libraries the weighing often ends with the security teams
available volunteer resources.
Best,
Chris