We now get (what appears to be; see libgcrypt announcement below) security bugs in Debian's 'gpg' as a consequence of Debian's 'gnupg' being stuck on the EOL'd 2.4.x branch, instead of tracking the current upstream-supported stable 2.5.x branch. Will forky ship with GnuPG 2.4.x too? The 2.4.x branch was declared deprecated quite some time ago, and the EOL date is 2026-06-30 rapidly approaching. I think the time is long overdue to move away from GnuPG 2.4.x and have Debian ship with GnuPG 2.5.x. So this is a bug report requsting that 'gnupg2' be updated to the stable branch of 2.5.x. I didn't see any similar bug already. Do you want help working on this? I could propose a 2.5.x branch targetted at experimental if you are open to accept help. Another approach is to package 2.5.x in a separate 'gnupg25' source package. Would you be open to that approach instead? I suppose the interaction with the 'gnupg2' package would be quite complex, so my gut feeling is that this isn't the best of solutions. /Simon Werner Koch via Gnupg-devel <gnupg-devel@gnupg.org> writes: [snip]