- Package:
- src:node-buble
- Source:
- src:node-buble
- Submitter:
- Jochen Sprickerhof
- Date:
- 2026-08-31 11:31:00 UTC
- Severity:
- normal
Hi, src:node-buble in unstable can't migrate to testing because the QA infrastructure couldn't reproduce the binary packages in unstable while it could reproduce the version in testing [1, 2]. Feel free to reach out if you need help debugging the problem. Alternatively you can ask the release team for an exception [3]. Cheers Jochen [1] https://qa.debian.org/excuses.php?package=node-buble [2] https://lists.debian.org/debian-devel-announce/2026/05/msg00001.html [3] https://lists.debian.org/debian-devel/2026/05/msg00383.html
Hello, Bug #1146092 in pkg-js-tools reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/js-team/pkg-js-tools/-/commit/7268e775137aace7ff17ed514009702607603f8b ------------------------------------------------------------------------ Make pkgjs-lock.json reproducible Modules flagged "test" in extlinks/extcopies are linked only when tests run, so the lock recorded node_modules/<dep> or /usr/share/nodejs/<dep> depending on the build options (Closes: #1146092). Always resolve them through nodepath, ie. keep the result a nocheck build gives. ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1146092
Hi Yadd, * Yadd <noreply@salsa.debian.org> [2026-08-31 11:06]: Thanks for working on this, though note that this happened in a regular build not using nocheck. Let's see if this fixes it. Cheers Jochen
Hello, Bug #1146092 in node-buble reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/js-team/node-buble/-/commit/998fa3704e73a4456cc2451b7cdf60910ad4abed The plugin's "auto" mode wraps a module in a lazy require*() depending on the order module loads complete, so acorn was inlined or wrapped at random. Closes: #1146092 ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1146092
Le 31/08/2026 à 13:10, Jochen Sprickerhof a écrit : Thank you for your work on reproducibility! You're right but I think the build should also be independent of the use of nocheck profile. The bug is really closed by node-buble 0.20.0...-6 (https://salsa.debian.org/js-team/node-buble/-/commit/998fa3) Cheers, Xavier
We believe that the bug you reported is fixed in the latest version of
node-buble, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1146092@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Xavier Guimard <yadd@debian.org> (supplier of updated node-buble package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 31 Aug 2026 13:03:30 +0200
Source: node-buble
Architecture: source
Version: 0.20.0+~0.20.5-6
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>
Changed-By: Xavier Guimard <yadd@debian.org>
Closes: 1146092
Changes:
node-buble (0.20.0+~0.20.5-6) unstable; urgency=medium
.
* Team upload
* Fix reproducibility: disable @rollup/plugin-commonjs strictRequires
(Closes: #1146092)
Checksums-Sha1:
4f7d01c44a8460f638a52aee59d00a0ee138784f 2759 node-buble_0.20.0+~0.20.5-6.dsc
f62657f69d697dcdbd51acea2aaeeb3c6b4173b0 9780 node-buble_0.20.0+~0.20.5-6.debian.tar.xz
Checksums-Sha256:
b16799a809f353d84449729de6981a4f2e61b5874624b45570599df5d6715fb1 2759 node-buble_0.20.0+~0.20.5-6.dsc
d952655a442506a56bad5ee51e2915c0403689ecd9f0cd562a5ae79cb001c654 9780 node-buble_0.20.0+~0.20.5-6.debian.tar.xz
Files:
6ae770a6a76b23c0b5f8b9655f5b7d0e 2759 javascript optional node-buble_0.20.0+~0.20.5-6.dsc
2478c3161eec48cc7fadbe372be77b41 9780 javascript optional node-buble_0.20.0+~0.20.5-6.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmqVYJsACgkQ9tdMp8mZ
7un8eQ/9FqT9Oj58NK8/D2Rj1nWG0l/XgY+ShOWf8MG/Y1fJSlAs/GNqcqSnSJCF
H45WYnEASZqkwT+zrufyCnkpZgAX1yFj5GGf+aiEsvOBfiT5WA0mxeJDSIOpE6gF
MCZFAEzj4ZdnEVgpc6URl1S6dW+57bgAVH72tfA0qQZ0uPUpKm7ceoRx7VvXRWKo
uMtDr3k7nieUsZVf5UX0cqeT9QP05IrOTso6kKAMRG9gqvMjoLhHkO40GcDIVHW9
Z372vrqv1x8V4dhqQecZGVPiv8tGHt7bSbRH7DZDiSCT6qRDxHg8ofAD1kcoM2Mz
bBLFcfDbAqkX40oLcS9Akh3C/wglwOTn27140lVfclKbIx5eIy9Kq/RD6Xx/zHow
PL1/PAFTC70O7gCkd3R7lqJainqu8tIwA+ZchhLJGeYvYI0ZRT22a3qfeDorsiyZ
iFHVnoRnigHZsu8zmfYP5VADEEkTGiO41GDURDStEbqbv/IawCPP1NRqXGpjImBH
Wz87IABDHkfI0x4pmi4AjThSDWIyAR/72HOr5mksT/AlQ1423Hkd5BwwOhT0GSI+
8T1EEoZ7phj+HcerLzBMzFCRVaCmKmwU8Ni9GA+CvKCbwjQGpTBymp76qhJvxp48
AHw+Y91LAmM8pt40qBlFWdhazxnc6ijSmDOuAx5EFuIIwMLmVZ0=
=nras
-----END PGP SIGNATURE-----
* Xavier <yadd@debian.org> [2026-08-31 13:15]: https://salsa.debian.org/js-team/pkg-js-tools/-/commit/7268e775137 seemed wrong. Thanks for your work on this! Cheers Jochen
Le 31/08/2026 à 13:15, Xavier a écrit : A reproducible test based on check/nocheck would have detect the xz attack (https://en.wikipedia.org/wiki/XZ_Utils_backdoor)
* Xavier <yadd@debian.org> [2026-08-31 13:24]: That would have been nice and https://tests.reproducible-builds.org/debian is using nocheck for one build now and there is ongoing work to add support for that in debrebuild https://salsa.debian.org/debian/devscripts/-/merge_requests/662/ and salsa-ci: https://salsa.debian.org/salsa-ci-team/pipeline/-/merge_requests/735 . I think it is too early to enable it on https://reproduce.debian.net/ already to block testing migration with it but we will surely get there. Cheers Jochen