#1149321 ITP: golang-github-moby-profiles -- AppArmor and seccomp profiles for containers

#1149321#5
Date:
2026-09-29 12:21:57 UTC
From:
To:
* Package name    : golang-github-moby-profiles
  Version         : 0.2.3+git20260828.61eaf32 (snapshot after tag seccomp/v0.2.3)
  Upstream Contact: Sebastiaan van Stijn <github@gone.nl>
* URL             : https://github.com/moby/profiles
* License         : Apache-2.0
  Programming Lang: Go
  Description     : AppArmor and seccomp profiles for containers

 This package provides the two Go modules of the moby/profiles repository,
 which hold the default security profiles the Docker engine and BuildKit
 apply to containers:
 .
  * github.com/moby/profiles/apparmor generates the default AppArmor
    profile ("docker-default") from a template and loads it with
    apparmor_parser;
  * github.com/moby/profiles/seccomp holds the default seccomp profile and
    turns a seccomp profile into the OCI runtime-spec representation,
    filtered by architecture, kernel version and capabilities.
 .
 Both modules were split out of the moby/moby source tree.

Binary package: golang-github-moby-profiles-dev (import paths
github.com/moby/profiles/apparmor and github.com/moby/profiles/seccomp).

Why: docker.io 29.8.1 (in preparation; unstable has 28.5.2, work in
progress at https://salsa.debian.org/mendezr/docker/-/tree/wip/moby-v29)
imports it from engine/daemon/seccomp_linux.go and
engine/daemon/apparmor_default.go (engine/go.mod: apparmor at 61eaf32,
seccomp v0.2.3), and BuildKit v0.33.0 from executor/oci/spec_linux.go. The
docker.io update is needed by github.com/anchore/stereoscope (ITP
https://bugs.debian.org/1135909).

I intend to maintain this package within the Debian Go Packaging Team.