Debian Package Tracker
Register | Log in
Subscribe

golang-github-notaryproject-notation-go

Sign and verify OCI artifacts (library)

Choose email to subscribe with

general
  • source: golang-github-notaryproject-notation-go (main)
  • version: 1.2.1-3
  • maintainer: Debian Go Packaging Team (DMD)
  • uploaders: Reinhard Tartler [DMD]
  • arch: all
  • std-ver: 4.7.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • testing: 1.2.1-3
  • unstable: 1.2.1-3
versioned links
  • 1.2.1-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • golang-github-notaryproject-notation-go-dev
action needed
Marked for autoremoval on 24 May: #1094409, #1104509 high
Version 1.2.1-3 of golang-github-notaryproject-notation-go is marked for autoremoval from testing on Sat 24 May 2025. It is affected by #1094409, #1104509. The removal of golang-github-notaryproject-notation-go will also cause the removal of (transitive) reverse dependency: golang-github-notaryproject-notation. You should try to prevent the removal by fixing these RC bugs.
Created: 2025-04-24 Last update: 2025-05-08 19:30
A new upstream version is available: 1.3.2 high
A new upstream version 1.3.2 is available, you should consider packaging it.
Created: 2024-12-18 Last update: 2025-05-08 17:00
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2024-56138: notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications. This issue was identified during Quarkslab's audit of the timestamp feature. During the timestamp signature generation, the revocation status of the certificate(s) used to generate the timestamp signature was not verified. During timestamp signature generation, notation-go did not check the revocation status of the certificate chain used by the TSA. This oversight creates a vulnerability that could be exploited through a Man-in-The-Middle attack. An attacker could potentially use a compromised, intermediate, or revoked leaf certificate to generate a malicious countersignature, which would then be accepted and stored by `notation`. This could lead to denial of service scenarios, particularly in CI/CD environments during signature verification processes because timestamp signature would fail due to the presence of a revoked certificate(s) potentially disrupting operations. This issue has been addressed in release version 1.3.0-rc.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Created: 2025-01-21 Last update: 2025-02-27 05:02
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2024-56138: notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications. This issue was identified during Quarkslab's audit of the timestamp feature. During the timestamp signature generation, the revocation status of the certificate(s) used to generate the timestamp signature was not verified. During timestamp signature generation, notation-go did not check the revocation status of the certificate chain used by the TSA. This oversight creates a vulnerability that could be exploited through a Man-in-The-Middle attack. An attacker could potentially use a compromised, intermediate, or revoked leaf certificate to generate a malicious countersignature, which would then be accepted and stored by `notation`. This could lead to denial of service scenarios, particularly in CI/CD environments during signature verification processes because timestamp signature would fail due to the presence of a revoked certificate(s) potentially disrupting operations. This issue has been addressed in release version 1.3.0-rc.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Created: 2025-01-21 Last update: 2025-02-27 05:02
1 bug tagged patch in the BTS normal
The BTS contains patches fixing 1 bug, consider including or untagging them.
Created: 2025-05-03 Last update: 2025-05-08 20:30
4 new commits since last upload, is it time to release? normal
vcswatch reports that this package seems to have new commits in its VCS but has not yet updated debian/changelog. You should consider updating the Debian changelog and uploading this new version into the archive.

Here are the relevant commit logs:
commit f98cafedf7415cb9bbe39981a60e6874cbec3ff4
Author: Reinhard Tartler <siretart@tauware.de>
Date:   Fri Dec 27 18:10:31 2024 -0500

    Update changelog for 1.2.1-3 release

commit ce6ea90e50da1df9ddf90d254ece6c5168022843
Author: Reinhard Tartler <siretart@tauware.de>
Date:   Fri Dec 27 18:04:48 2024 -0500

    Skip tests that fail on unknown certificate status

commit d5a5377e21515a94b027a3eac2e2c7cd98a7b9c8
Author: Reinhard Tartler <siretart@tauware.de>
Date:   Thu Dec 26 12:08:11 2024 -0500

    install extra testdata to fix FTBFS

commit b4eb4d369bd433c3925d4eb0e3220b9a362e32e0
Author: Reinhard Tartler <siretart@tauware.de>
Date:   Fri Dec 27 18:04:37 2024 -0500

    normalize patches
Created: 2024-12-28 Last update: 2025-05-03 07:31
lintian reports 1 warning normal
Lintian reports 1 warning about this package. You should make the package lintian clean getting rid of them.
Created: 2024-12-28 Last update: 2024-12-28 10:31
debian/patches: 3 patches to forward upstream low

Among the 4 debian patches available in version 1.2.1-3 of the package, we noticed the following issues:

  • 3 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2024-12-18 Last update: 2024-12-28 09:31
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.2 instead of 4.7.0).
Created: 2025-02-21 Last update: 2025-02-27 13:25
news
[rss feed]
  • [2024-12-31] golang-github-notaryproject-notation-go 1.2.1-3 MIGRATED to testing (Debian testing watch)
  • [2024-12-27] Accepted golang-github-notaryproject-notation-go 1.2.1-3 (source) into unstable (Reinhard Tartler)
  • [2024-12-26] Accepted golang-github-notaryproject-notation-go 1.2.1-2 (source) into unstable (Reinhard Tartler)
  • [2024-12-17] Accepted golang-github-notaryproject-notation-go 1.2.1-1 (all source) into unstable (Debian FTP Masters) (signed by: Reinhard Tartler)
bugs [bug history graph]
  • all: 2
  • RC: 2
  • I&N: 0
  • M&W: 0
  • F&P: 0
  • patch: 1
links
  • homepage
  • lintian (0, 1)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.2.1-3

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing