Hello Vincent,
The changes were not ready in time for the point release. The fix for this
issue will arrive with 33 CVE fixes, which also introduced a few regressions
and delayed everything.
I've just uploaded rsync 3.5.0+ds1-3 to Debian Unstable. It contains the
regression fixes I was waiting for, I'm going to wait a couple of days and then
send the same changes to Debian 13/Trixie as a security update, so you won't
have to wait until the next point release.
I had the choice of just backporting the patches to Debian 13, but my judgment
call is that it's less risky to just bump to 3.5.0, backporting all of the
fixes it's already quite close to 3.5.0 in practice.
Regarding behavior changes for the update, you can read them
here: https://salsa.debian.org/debian/rsync/-/blob/debian/master/debian/rsync.NEWS?ref_type=heads#L1-94
The behavior changes stem from the CVE fixes themselves, not from the
3.5.0-only changes.
I'm looking into backporting the same fixes to Debian 12/Bookworm, but one
issue with the backports is still pending, so I'm prioritizing 13/Trixie first.
Thanks,