-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 17 Dec 2024 23:41:19 +0100 Source: apt Architecture: source Version: 2.9.17+exp1 Distribution: experimental Urgency: medium Maintainer: APT Development Team <deity@lists.debian.org> Changed-By: Julian Andres Klode <jak@debian.org> Closes: 1090068 Changes: apt (2.9.17+exp1) experimental; urgency=medium . * Fix out-of-bounds read in `apt show :` (Closes: #1090068) * gpgv: Extract VerifyDetachedSignatureFile() * Switch to sqv for OpenPGP verification: - methods: New sqv method. - acquire: Use the sqv method if an sqv binary is found at build time. - test: Various adjustments for changed outputs - debian/control: Use sqv instead of gpgv * Incompatibilities: - Output for gpgv methods is slightly different - The APT::Hashes feature is not supported, policy is handled by Sequoia - The Signed-By feature no longer supports exact subkeys (with !). Checksums-Sha1: f1564e529130b4550047a65f530b1e5c4e494f6d 3028 apt_2.9.17+exp1.dsc 521fdaf6bb26209f173a2d0ed9ac43ada4d68c33 2392644 apt_2.9.17+exp1.tar.xz a86e8f0215f400fbfc4191401f0fc21c1ea509bc 7964 apt_2.9.17+exp1_source.buildinfo Checksums-Sha256: 26084b8e1dd5a1df3dc0ac23c74299e7be7a8c6799a2003845665340927a8ddb 3028 apt_2.9.17+exp1.dsc 214b8f2271a706b8d8814464bc3a93fe9975dd9f09c242f384e95a0ecc5b92cd 2392644 apt_2.9.17+exp1.tar.xz 0a03a97c904f11ffaa1163f5989b5cb22030c2a097a752005226a713222788ac 7964 apt_2.9.17+exp1_source.buildinfo Files: 32006d06c8d80366b6ee4e4c98790fb7 3028 admin required apt_2.9.17+exp1.dsc 70de754c26e52e86f73e9278a3a2eb05 2392644 admin required apt_2.9.17+exp1.tar.xz 5026707674ebe2e5902d76408c629c1a 7964 admin required apt_2.9.17+exp1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJDBAEBCgAtFiEET7WIqEwt3nmnTHeHb6RY3R2wP3EFAmdiAEgPHGpha0BkZWJp YW4ub3JnAAoJEG+kWN0dsD9xyGAP+wYfaaRpUYuIPrcx8a9shceXWZjD+T0Cla1s iPMXnBk9CJUlQCMt+US/t6L/8WYWMyK0Fg93iDx4ZtWd8ZFUapbDA0DIqBE1H6Dn pw/vrWdsjb/Cjv2OpqvbLqPBXgG0ZN4qyiKKRjGHKzUGjz9xxl6Wsds0KR8arl7d RtG+Cy4/qpyYfs8kbCLgtwcuCRF27CkERPMc/EJ64YmPN4WDtXEF4klVOP/rnEbB lI1pX8biK6mDDPmID4+RjF0B9B5aJzgM/gJN6yEZZfro2U1XNc5OYgCuVmhN64H1 RpPD8+ITxuIdYLiLmX3QVnSLqbYCVLt1kAJb9i8EnICAk0zWRnnchIzEVvX7vepe ZRN8VGuB4EB7a9PUgmntdzmznFwtderEifhj9QpXF2xLMkedAkju2GNWco4JnAsi wLwF82ArUQ1AWBgeWt2IvXXlFCJUOIPZowXZsgjIA4YzN0Iur2XMzexU6urxe75O M/2g+XOYgmSOJVvCddI/2bm2mZpTOY/r8warRimXEtHDUHcEsU2IaQ7OvBh4+yme FM3CITPZV8QNfvxboE9DWSmTP7p9WKZRqhXbNc9uxnsrLBAU5W53xYFZKiCGxadn RfBDZ3Y0tyPqxEDsdQC+2DpuOWep1OUsB8vQZcbj7BDvV2VnK6eonua8QwG1XWcv Bcoo+rl0 =TCcz -----END PGP SIGNATURE-----