[ Reason ]
This update includes 3 upstream patches fixing 3 CVEs published for
goaccess.
[ Impact ]
goaccess is a web server log analysis tool. Specially crafted requests
can explore those vulnerabilities and cause it to overwrite memory or
crash.
[ Tests ]
There is no regression in the (admittedly simple) autopkgtests.
[ Risks ]
The changes were cherry-picked from upstream, applied cleanly over the
trixie branch, and are very targeted and localized.
[ Checklist ]
[x] *all* changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in (old)stable
[x] the issue is verified as fixed in unstable
[ Changes ]
The main change is adding 3 upstream patches cherry-picked from the
latest upstream release. The change to debian/salsa-ci.yml is necessary
to prevent a failure on Salsa CI related to uscan (debian/watch is fixed
in the sid/forky version of the package).
[ Other info ]
This was marked as no-DSA by the Security team so I'm going with a
stable update.
I'm attaching both the full diff against the version in trixie, and the
actual patches since those are easier to read than the diff-in-diff
version in the full diff.