-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Wed, 19 Jan 2022 17:04:30 GMT Source: flatpak-builder Architecture: source Version: 1.0.12-1+deb11u1 Distribution: bullseye-security Urgency: high Maintainer: Utopia Maintenance Team <pkg-utopia-maintainers@lists.alioth.debian.org> Changed-By: Simon McVittie <smcv@debian.org> Changes: flatpak-builder (1.0.12-1+deb11u1) bullseye-security; urgency=high . * d/gbp.conf, Vcs-Git: Configure for bullseye stable updates * d/p/Disable-filesystem-access-with-nofilesystem-host-reset.patch, d/p/Allow-nofilesystem-host-reset-in-flatpak-builder-run.patch: Add patches from upstream to prevent unintended access to host filesystem (CVE-2022-21682). To be effective, this also requires an updated version of flatpak. * d/control: Bump flatpak dependencies to 1.10.7. This ensures that we have the version that enables us to avoid CVE-2022-21682. Checksums-Sha256: 6a2e4556b687d3c88ff7f1747c90c856cffd44df6be214b33666e869eb6321fd 2855 flatpak-builder_1.0.12-1+deb11u1.dsc 17a473d4dc30670fa93f86ea85bdebb3d70bd57bb63b736d99e5b2c43afb4e83 8832 flatpak-builder_1.0.12-1+deb11u1.debian.tar.xz 76337c25bb15286026a6501f6b9aef7b803b8a96e039bc1353c00c44e04b716c 10755 flatpak-builder_1.0.12-1+deb11u1_source.buildinfo 4780c1b8e0838ffb64e9639bd7801417964fd818c7c6d5e9afca4d5511ded2c8 459764 flatpak-builder_1.0.12.orig.tar.xz Checksums-Sha1: f5a6f6792c424a962d7ce7585010c84c81cec3c1 2855 flatpak-builder_1.0.12-1+deb11u1.dsc 010960be1020f8f08ea083aea01c3c92c1b01fb4 8832 flatpak-builder_1.0.12-1+deb11u1.debian.tar.xz a891aa5cefeef948bd998953b7474989c9bcecdf 10755 flatpak-builder_1.0.12-1+deb11u1_source.buildinfo 71b27eb92ba69c41a2ba24f4c10229b3948431f2 459764 flatpak-builder_1.0.12.orig.tar.xz Files: 729687d250b180afeca4822b3a1efab5 2855 devel optional flatpak-builder_1.0.12-1+deb11u1.dsc 17355cfdfc25b1515179b5776f52cf3d 8832 devel optional flatpak-builder_1.0.12-1+deb11u1.debian.tar.xz 21945017cfb6aec858c7d5c35f58a658 10755 devel optional flatpak-builder_1.0.12-1+deb11u1_source.buildinfo 83583c2e34837575a882aca11b2e1dd0 459764 devel optional flatpak-builder_1.0.12.orig.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEENuxaZEik9e95vv6Y4FrhR4+BTE8FAmHoRKcACgkQ4FrhR4+B TE/+3w//fPMTo/5oiCDwuoiF8WfiyDUOXgTqsFfyvkoa3wonKFf5dfGeaUVq3I1o 0D6psouC+qqOGTKg2NFKcu7fLzjUBW/yXNDa5W9r6kaBIJ2mCUzX7kXEpw2Avyiy Oai7DkjzgkedUp9kMV/aFel5znLRuMX2x6pk/q2Bp4LMIKS+9Z4vdSDO6aIkAqg4 E4lNHHD47JkH3y9catI0R9+8UrMu7YB6MgiWjI3PqgtBN0BDPkUDMfbJN18G38o1 kbGziLSSA63xQ9uEDWvFb9b+NZLRhPy/7jhyRCG9KwaSY2UJTFdZQrEOqSW1k7yS XvT8V9a04YypiWmEYO1TwaUYcEeSEKDF9B/pu/LSiwmUFdvddwopjPCDq4olEW7I U4AFi+787x5qCB9bcLavIBhi6EV3wadqP+EVFB2jq1VQPD7e+d9iOuGJuTb4hXSz V0vy4wnmQr9/Eg75Fz2K/IzHYOGPd0KmLVf4/bbwIwaTybjJX6kEiPZ38YedbbEn Z1u+SyU5OMxMyXpuvwwtiec3pId7AhbMiMAZerVi1xXataPNNG27u/RHSACIQ/8A YHclk6VvmQSfTJiu1J4O9EymcAovXoeqZeUASSEMJb/LNdVE2sR6fzu1PQzV9hkP vdtlJnzN/x0/XQnlQOBtHEjaPW9alojZ1JjISbiUnt9Rlgxm3Rk= =zw1b -----END PGP SIGNATURE-----