#1144930 trixie-pu: package watcher/14.0.0-1+deb13u1

#1144930#5
Date:
2026-08-20 15:31:05 UTC
From:
To:
Hi,

[ Reason ]
I would like to upload watcher watcher/14.0.0-1+deb13u2 to
address this upstream issue:
https://security.openstack.org/ossa/OSSA-2026-036.html
aka:
https://bugs.debian.org/1144880

[ Impact ]
As per upstream announce:
Watcher does not apply authorization to its webhook trigger
endpoint. Any authenticated user who learns an audit’s
webhook URL, for example from the Aodh alarm metadata leaked
above, can start an EVENT audit and its associated action
plan regardless of their own project or role.

[ Tests ]
Upstream patch includes new tests, also run at package
build time. I do not run Watcher myself in production, though
upstream also runs functional testing to validate new patches.

[ Risks ]
Patch is not very big.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

[ Changes ]
(Explain *all* the changes)

Please allow me to upload watcher/14.0.0-1+deb13u2.

Cheers,

Thomas Goirand (zigo)