- Package:
- src:xapian-omega
- Source:
- xapian-omega
- Submitter:
- Matthew Vernon
- Date:
- 2022-07-08 02:51:03 UTC
- Severity:
- important
Dear maintainer, Your package still depends on the old, obsolete PCRE3[0] libraries (i.e. libpcre3-dev). This has been end of life for a while now, and upstream do not intend to fix any further bugs in it. Accordingly, I would like to remove the pcre3 libraries from Debian, preferably in time for the release of Bookworm. The newer PCRE2 library was first released in 2015, and has been in Debian since stretch. Upstream's documentation for PCRE2 is available here: https://pcre.org/current/doc/html/ Many large projects that use PCRE have made the switch now (e.g. git, php); it does involve some work, but we are now at the stage where PCRE3 should not be used, particularly if it might ever be exposed to untrusted input. This mass bug filing was discussed on debian-devel@ in https://lists.debian.org/debian-devel/2021/11/msg00176.html Regards, Matthew [0] Historical reasons mean that old PCRE is packaged as pcre3 in Debian
We believe that the bug you reported is fixed in the latest version of
xapian-omega, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 999927@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Olly Betts <olly@survex.com> (supplier of updated xapian-omega package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 08 Jul 2022 14:15:12 +1200
Source: xapian-omega
Architecture: source
Version: 1.4.20-1
Distribution: unstable
Urgency: medium
Maintainer: Olly Betts <olly@survex.com>
Changed-By: Olly Betts <olly@survex.com>
Closes: 999927
Changes:
xapian-omega (1.4.20-1) unstable; urgency=medium
.
* New upstream release.
* debian/copyright: Remove trailing whitespace.
* debian/rules: Fix to run the upstream testsuite (accidentally disabled by
refactor to use dh in 1.4.18-2).
* debian/rules: Fail if there are files installed by the upstream build
which aren't handled by the packaging (like we did before the dh
refactor).
* debian/control.in: Mark conformance with policy 4.6.1.
* debian/control.in: Update PCRE dependency to PCRE2, which is supported
by this new upstream version. (Closes: #999927)
Checksums-Sha1:
b7004d2d69e749bf73a6909213e1c84d315edd78 2018 xapian-omega_1.4.20-1.dsc
5daf3d5f28ce80f82245fa2fa13350d902ee2890 563324 xapian-omega_1.4.20.orig.tar.xz
526cfccc55a26b2c45091121bb3226c8fb54a9d0 14644 xapian-omega_1.4.20-1.debian.tar.xz
786bc02773d34d2c4158c1762d8b5dcb905ad9c1 6543 xapian-omega_1.4.20-1_amd64.buildinfo
Checksums-Sha256:
f735973131ef5781a5267ed9d4604b93d2b6222f044045d7ca9bd86318e7d2b5 2018 xapian-omega_1.4.20-1.dsc
09fd7d6c60b394fd00d84700649969a1fcc3aa2b88bb2c6ca220fdfa8d25881f 563324 xapian-omega_1.4.20.orig.tar.xz
f52f19fcd4d631c0a059d49972480a3785cf34e23a10b92409822aef40bd29b0 14644 xapian-omega_1.4.20-1.debian.tar.xz
f4d27aadb75bdb02fbafd3bc3ae7ea137a22dce70141049fd3731a2061d891ee 6543 xapian-omega_1.4.20-1_amd64.buildinfo
Files:
af541c03a59f7f4322c108758265ce45 2018 web optional xapian-omega_1.4.20-1.dsc
11542c425deea413933827701bd10b91 563324 web optional xapian-omega_1.4.20.orig.tar.xz
f9e1ac8cba850374e45ee2d452cda975 14644 web optional xapian-omega_1.4.20-1.debian.tar.xz
1f296d946faea5bc08b3344e3e39b77e 6543 web optional xapian-omega_1.4.20-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEECOJAD/f+j+3jrLUoGBR7BzutKwcFAmLHmOcACgkQGBR7Bzut
Kwc5XBAArIzI642tRd8iRbonAKkuZe/1LAuhMiuvZZuGKGblbchIO9oTxDFGtBIz
JoGoInEVzj9Mjpygqzqt7rzelaHVwU0Vfn7Hw6LlFHkGT8ozL8rqb7M7EYa43tdD
Jc5K3cEf/8FnuqQQ8a6oD/gKsPrxLxFVrIZn9+f0/AcNZ/CdsRVzPYOEV7gHgTLF
peH66hHKVrEDsOo7AScxEabbP/bgFvr/H0oUGSaYNbAxi/syokF+nvEiLjtm7//V
qB3mHURuVH7X/+CWeC7imQPIdHIAlz0msPb5QwtX8pCvDA9yBWnuaq6CKZslENbI
bbuKJ1FzxYe8uhJc+QDYORjdaXRqKgf1fqOFCsDvFz8oQR4rTAIUSQAyHch0xbFY
8u8ilYIcVlGodk1v8JXwWlfLADEsiaKh+awDQ9RoGW594JELOVNuor8GzqhjgSet
XGZWjONpIeTuo0/Y8b7xX3Ue1O3AGLMEP/wD72txSoxs2nLUp5z8OSikYieyyY5V
+jTzKTJ427Ahcb7kCib/J6GjEkG6vIuKKp7bZEfMNMzOt3Ytgbd+AnlSQxk3040+
n5Kz6NcDDry/gz4Hac6riX61NOi9qfrCYPgrPbjdONlC+JRleV9pDBNxscrG0HLA
SCIonpirHdljr0KZ+boO1+OJ2U3BMYaspDAjZsPd8rMfOGG+uPg=
=9waX
-----END PGP SIGNATURE-----