-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 18 Jan 2022 01:45:47 -0700 Source: golang-github-microcosm-cc-bluemonday Binary: golang-github-microcosm-cc-bluemonday-dev Architecture: source all Version: 1.0.16-1~bpo11+1 Distribution: bullseye-backports Urgency: medium Maintainer: Debian Go Packaging Team <team+pkg-go@tracker.debian.org> Changed-By: Anthony Fok <foka@debian.org> Description: golang-github-microcosm-cc-bluemonday-dev - Go library for scrubbing user generated data of unapproved html Changes: golang-github-microcosm-cc-bluemonday (1.0.16-1~bpo11+1) bullseye-backports; urgency=medium . * Rebuild for bullseye-backports. . golang-github-microcosm-cc-bluemonday (1.0.16-1) unstable; urgency=medium . * New upstream version 1.0.16 + CVE-2021-42576: The bluemonday sanitizer before 1.0.16 for Go, and before 0.0.8 for Python (in pybluemonday), does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements. See https://github.com/microcosm-cc/bluemonday/commit/c788a2a . golang-github-microcosm-cc-bluemonday (1.0.6-1) unstable; urgency=medium . * New upstream version 1.0.6 * Change Section from devel to golang * Bump Standards-Version to 4.6.0 (no change) * Add myself to the list of Uploaders * debian/gbp.conf: Set debian-branch to debian/sid for DEP-14 conformance * Remove debian/patches/01_the_tests_are_perpetually_broken.diff as TestIssue51 is no longer broken in v0.2.0 * Add dependency on golang-github-aymerick-douceur-dev (>= 0.2.0) as per go.mod * Mark library package with "Multi-Arch: foreign" Checksums-Sha1: 68f5e5462749b0f9b4e12384805322f4d4f93f03 2554 golang-github-microcosm-cc-bluemonday_1.0.16-1~bpo11+1.dsc 251a010c419bb922787e81dcdf0adf1092ae0f95 3524 golang-github-microcosm-cc-bluemonday_1.0.16-1~bpo11+1.debian.tar.xz b44d09fcba1a3145abebc10bec1f891e0adae94b 112116 golang-github-microcosm-cc-bluemonday-dev_1.0.16-1~bpo11+1_all.deb 80604ef4accf53fb1addd49ddb3532ca3e79e30a 6806 golang-github-microcosm-cc-bluemonday_1.0.16-1~bpo11+1_amd64.buildinfo Checksums-Sha256: 577ce7fcdb0284aef39597e9fabf88399057fea7168c7433d064680eb6439e20 2554 golang-github-microcosm-cc-bluemonday_1.0.16-1~bpo11+1.dsc f78e2419ebbe87e3034da016568bb8fcdfa35a4e3b3091bd18749ddb0773b780 3524 golang-github-microcosm-cc-bluemonday_1.0.16-1~bpo11+1.debian.tar.xz e4767246f64541e2c56fc64199fffb847416fc050cff73b6ba02a37b71b9d9de 112116 golang-github-microcosm-cc-bluemonday-dev_1.0.16-1~bpo11+1_all.deb e3c624fe7d57b7af2e51684194cc000c561f34add80fa84193aaba8c21c2c898 6806 golang-github-microcosm-cc-bluemonday_1.0.16-1~bpo11+1_amd64.buildinfo Files: 649afb0821f213e3666b6819d2b778da 2554 golang optional golang-github-microcosm-cc-bluemonday_1.0.16-1~bpo11+1.dsc d8eeb584944bf7ced495b08c9e3326c7 3524 golang optional golang-github-microcosm-cc-bluemonday_1.0.16-1~bpo11+1.debian.tar.xz 0dccafd6d230d5ef27eb2652e44e1d5a 112116 golang optional golang-github-microcosm-cc-bluemonday-dev_1.0.16-1~bpo11+1_all.deb d8d666eed91149f599803c4b1c8371a2 6806 golang optional golang-github-microcosm-cc-bluemonday_1.0.16-1~bpo11+1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQJEBAEBCAAuFiEEFCQhsZrUqVmW+VBy6iUAtBLFms8FAmH08GAQHGZva2FAZGVi aWFuLm9yZwAKCRDqJQC0EsWaz5ChD/wNaW9sZtW8mRyruc7eqSo7Cee74nn6tjM+ Uvf3wNw9WLBc+FHc0IucRZlITqc/MNqVIH8dmigkySHoB/MeiZd97dTKTpgqb342 iXe+4ZXbfMxiNXZAIBJTfOBJBODjf96UcrJRVpILQabVgfpNZ9CJ28O9dUN2uOeG 9OIfpkQA25EqIPEsWkZN1anwtMkfP/aH8jCpnY0lQY0ZU1p37adY8bja7VC0rYdD 0v1qVynDdpbi0t0noK52keM4Tmk5ygBSoJW6HCsdk4hKBMNM+/5xqgbx/da16bnw DBCgKhRpVjRUBwbRz/jNVFoIbE6508+eQaHJFfJucZAUxi2Ct7XItVJyqGN7efQd 0mKYpRPUKg7uJjqLX1zrK+3E2dF0Zgq+Rb+Hu6NIU8h5L/s/iZDEEonLJOBLLazE 7OymLAhEgAIGyYcQFNjDrIYzyY1MXSEhxubZNs2IembVkwgCpIAcAROtBCzmUjVB 7vwFFonDNEfxjVN2vic9ovaZVxsTiF0Dh65lW9IR/nnwiq0ArmDFwWkkyE64MAUs ZA0EZrerpc2/yrPMUI7oFTsKnMUcZemPHj1lVFCRIM3TBH9Y9T5P1TScED+ooaiX vbYUNUO8tI1Ha7nmoAF7w1vUIdLREy8Vh7FO4HRYrsUXphnHnyY9Pgjpb0PfyuQU bhKdWBZIYQ== =9BAY -----END PGP SIGNATURE-----