#1149348 ITP: golang-github-googlecloudplatform-confidential-space -- Confidential Space verifier server utilities (Go)

#1149348#5
Date:
2026-09-29 14:47:21 UTC
From:
To:
* Package name    : golang-github-googlecloudplatform-confidential-space
  Version         : 0.0~git20260915.a6c0685+ds-1
  Upstream Author : Google LLC
* URL             : https://github.com/GoogleCloudPlatform/confidential-space
* License         : Apache-2.0
  Programming Lang: Go
  Description     : Confidential Space verifier server utilities (Go)

 Confidential Space is a Google Cloud environment for running workloads on
 confidential virtual machines with hardware-based remote attestation. This
 Go module (the "server" directory of the upstream repository) provides the
 verifier server utility libraries that a Verifier Service uses when
 validating Confidential Space attestations: validating Google-issued
 service account ID tokens (gcpcredential), verifying attestation event logs,
 checking signed container images and related helpers.
 .
 Only the "server" module of the upstream repository is packaged; the codelabs
 tutorials (16 MB of sample data) and the small, separate ovmf_extraction_tool
 helper module are excluded via a +ds repack.

Reasoning: this module is part of the Go module dependency graph of the
OpenTelemetry Collector, which is being packaged for Debian. It is reached
only through go-tpm-tools' go.mod: "go mod why" confirms that no Collector
package -- and no other package in Debian -- actually imports it. Under the
module-aware dh-go build system the whole module graph must nevertheless
resolve locally, so the source of this module has to be present even though it
is never compiled on Debian's architectures.

The packaged snapshot is pinned to the exact upstream commit the Collector
requires through go-tpm-tools 0.4.10 (go module version
v0.0.0-20260915221818-a6c0685fb9fc); all of its Go dependencies are already in
Debian. It is shipped as source only -- nothing in Debian compiles it, and
Debian ships several of its dependencies newer than this snapshot pins. I
intend to maintain it inside the Debian Go Packaging Team.