-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 21 Jan 2025 19:53:51 +0100 Source: node-undici Binary: libllhttp-dev libllhttp9.2 node-llhttp node-undici Architecture: source amd64 all Version: 7.2.3+dfsg1+~cs24.12.11-1 Distribution: experimental Urgency: medium Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org> Changed-By: Jérémy Lal <kapouer@melix.org> Description: libllhttp-dev - HTTP messages parser library dev files libllhttp9.2 - HTTP messages parser library node-llhttp - HTTP client sources for Node.js node-undici - Node.js HTTP/1.1 client Changes: node-undici (7.2.3+dfsg1+~cs24.12.11-1) experimental; urgency=medium . * New upstream version 7.2.3+dfsg1+~cs24.12.11 * CVE-2025-22150: Uses Insufficiently Random Values * Standards-Version 4.7.0 * Bump libllhttp soname to 9.2 * copyright: update paths * rules: remove extra LICENSE * lintian-overrides: fix paths * patches: remove unapplied * rules: clean Checksums-Sha1: 6fd0092fd7f57c9e75b413b69d6256d22766a939 4707 node-undici_7.2.3+dfsg1+~cs24.12.11-1.dsc 46b46af6495b75a900886a20879c5de0543c5e5c 2772 node-undici_7.2.3+dfsg1+~cs24.12.11.orig-binary-search.tar.xz 330196935b4cf6261978426ba45c487eafa50fa5 39820 node-undici_7.2.3+dfsg1+~cs24.12.11.orig-fastify-busboy.tar.xz ef48cda13fd92796204586a0ff32b34d062c378a 5900028 node-undici_7.2.3+dfsg1+~cs24.12.11.orig-llhttp.tar.xz 45faa0054d37a1b6a6a463a428fb6d0cb6a8c23f 27872 node-undici_7.2.3+dfsg1+~cs24.12.11.orig-llparse-builder.tar.xz 0f1a8a40daf6fb490f3c283448085ce013d09716 28840 node-undici_7.2.3+dfsg1+~cs24.12.11.orig-llparse-frontend.tar.xz 61d3690843470b12531fbbc6ebf3587405d22151 34392 node-undici_7.2.3+dfsg1+~cs24.12.11.orig-llparse.tar.xz 01ffa381065090d1221f0f03fd8346424504e9fe 1774060 node-undici_7.2.3+dfsg1+~cs24.12.11.orig.tar.xz 5bf11a184279372d06283198087a34ccca2c9804 214900 node-undici_7.2.3+dfsg1+~cs24.12.11-1.debian.tar.xz a8b99a9ad976dfb36582208722a058779e96683a 39856 libllhttp-dev_9.2.1~7.2.3+dfsg1+~cs24.12.11-1_amd64.deb e14fedc9d9529d3d73799842a0c218f168067a2b 33472 libllhttp9.2_9.2.1~7.2.3+dfsg1+~cs24.12.11-1_amd64.deb d91602509a8c9279dd29351c3ed1ecb41642578b 127888 node-llhttp_9.2.1~7.2.3+dfsg1+~cs24.12.11-1_all.deb a2d3a6b4e31557cd3226045cf8d78d22b0cefdd5 332436 node-undici_7.2.3+dfsg1+~cs24.12.11-1_all.deb 879a2fd01d7c1fd8b280d109411297a70fa88017 11166 node-undici_7.2.3+dfsg1+~cs24.12.11-1_amd64.buildinfo Checksums-Sha256: 00f4ba048082dab6f85c3aa36c7fb3fada55b81c4cd8bd7042d19cc4d2ecc510 4707 node-undici_7.2.3+dfsg1+~cs24.12.11-1.dsc 4c722d476f84b280160bfc428aa36e2806f9837902a43cda7caaa401c2a52f54 2772 node-undici_7.2.3+dfsg1+~cs24.12.11.orig-binary-search.tar.xz d3e5c5dfc8aba040287b99e267ecdbea45a822f04f2cb3837e4662deeb32c2c6 39820 node-undici_7.2.3+dfsg1+~cs24.12.11.orig-fastify-busboy.tar.xz 9bd346147fa1f7ac096360620189b30284a5537bfbdf8db9da40ed12fe3fe42a 5900028 node-undici_7.2.3+dfsg1+~cs24.12.11.orig-llhttp.tar.xz 48fc4ad3744179216d30f36e22a4e72bd11b6f47165f1bd22144436ba535b8f3 27872 node-undici_7.2.3+dfsg1+~cs24.12.11.orig-llparse-builder.tar.xz 30e1c7809fc5b31bf63e8f3b6eaa8ff0f08910fa131294d46a3f33c849fd7f0e 28840 node-undici_7.2.3+dfsg1+~cs24.12.11.orig-llparse-frontend.tar.xz ca5062636558b8171ef7309fa829179258d2fb04914ade2ba663ce42970fe32a 34392 node-undici_7.2.3+dfsg1+~cs24.12.11.orig-llparse.tar.xz caa45974d0147481c033a5fdf318bc8835cff458bd2a02d9d9a878a944274d84 1774060 node-undici_7.2.3+dfsg1+~cs24.12.11.orig.tar.xz 8c7335560400c6691e12bf6ae57e2a1af11476b2c001336a90b096e6dddbd5f8 214900 node-undici_7.2.3+dfsg1+~cs24.12.11-1.debian.tar.xz e8ed19beb9acb0b4f883377db41a8acb7da2cf402de2873c93b2e859da880120 39856 libllhttp-dev_9.2.1~7.2.3+dfsg1+~cs24.12.11-1_amd64.deb b4127ed657af59664ca3fc02764b13296685ed066e2beef378c355d615b9d56a 33472 libllhttp9.2_9.2.1~7.2.3+dfsg1+~cs24.12.11-1_amd64.deb 266cfc66431610d6f018d7c89c0cca1b3317aebcfd35234b7b45d8835ecb2972 127888 node-llhttp_9.2.1~7.2.3+dfsg1+~cs24.12.11-1_all.deb 4d69e69eec5a2dbee18877fc793c26fe730d8c8163a7993769c9c73326913557 332436 node-undici_7.2.3+dfsg1+~cs24.12.11-1_all.deb 18c562eadef54b6bd1c930b4a966e1f74aae7463cf10eaaccfb1fd57df21429e 11166 node-undici_7.2.3+dfsg1+~cs24.12.11-1_amd64.buildinfo Files: 3dc75aa7129fbdb933a0644ee186767f 4707 javascript optional node-undici_7.2.3+dfsg1+~cs24.12.11-1.dsc 00109915720120e4ee6ade7582b2b365 2772 javascript optional node-undici_7.2.3+dfsg1+~cs24.12.11.orig-binary-search.tar.xz 94597c871b16a404e1bdcb23d0cb7bc1 39820 javascript optional node-undici_7.2.3+dfsg1+~cs24.12.11.orig-fastify-busboy.tar.xz bc4748a7440fd00f978b48379d8777c5 5900028 javascript optional node-undici_7.2.3+dfsg1+~cs24.12.11.orig-llhttp.tar.xz af1818fe0c7e2939d19e35f3e7f80f91 27872 javascript optional node-undici_7.2.3+dfsg1+~cs24.12.11.orig-llparse-builder.tar.xz ebf8b8761d2ec86b375e5f0c0be1b320 28840 javascript optional node-undici_7.2.3+dfsg1+~cs24.12.11.orig-llparse-frontend.tar.xz 825b830bb267ecbcb761428a7b4c80e1 34392 javascript optional node-undici_7.2.3+dfsg1+~cs24.12.11.orig-llparse.tar.xz d75c20f01952964b93c9e590678aeb18 1774060 javascript optional node-undici_7.2.3+dfsg1+~cs24.12.11.orig.tar.xz 60bcca331aafd22dd81f6600eb671443 214900 javascript optional node-undici_7.2.3+dfsg1+~cs24.12.11-1.debian.tar.xz f97ded29b3ea081c72f2b4ad5280160e 39856 libdevel optional libllhttp-dev_9.2.1~7.2.3+dfsg1+~cs24.12.11-1_amd64.deb 6d7e03b0efcbb7847d9ca521e7090e6b 33472 libs optional libllhttp9.2_9.2.1~7.2.3+dfsg1+~cs24.12.11-1_amd64.deb 2251048c1f34b03cb46037c4c0387db9 127888 javascript optional node-llhttp_9.2.1~7.2.3+dfsg1+~cs24.12.11-1_all.deb f98545b16a0a9635d8e6ad1167615b78 332436 javascript optional node-undici_7.2.3+dfsg1+~cs24.12.11-1_all.deb 4b17ac645f10c8b7ac0fb265a51a824e 11166 javascript optional node-undici_7.2.3+dfsg1+~cs24.12.11-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQJGBAEBCAAwFiEEA8Tnq7iA9SQwbkgVZhHAXt0583QFAmeQN7sSHGthcG91ZXJA bWVsaXgub3JnAAoJEGYRwF7dOfN0rEYP/A9eK873oeaPxzjA+LPFVuCVJNVFlL7S 7KvNiGsY12SX7NauW3vKDmzB9/Or2XLr5nNma2sY4ePDEDy6Wv6pNhkk0/Z6/U7r dlsr5NL+cD685um6zseDwpHndsprSlWkGpcDYBkN2tT9XVC3MaXlpve+FNRMZ0YH cRQpNvR6kXGHGIvZ9v6z1s30peIE8ohm3KJpkzZH/tICKkgvjM8e0zPG7bTLI80s bfx+7RcjVBSbNpIei5tMfex3ZgodMeIGdTseN0fENiCYZWxnhZJeqcK/QkdFT7IF a+eiSY/iZRTqf/ufhg3v+TFPaJMAz+UdEI9G+BO0neH+qQdpOmUyj67ki60EzHkn +Ae5TL0bWgiH/C9e2AmYvnmg8DCSbFGtrFP6zc8fHwbHqUu0lZGUreZra5tx/vtB AbSCCOFi8SkMNS1tf/kn/DhxLFC1qUmidEjX/l3I4xMFgHP9cqXSiYVQa6v/ZRNx lpuZqoCM9NHISet7Aeu3x+q3s8eVCic2/ZED9AueCLvslb3WVLoTX0gd103HUFMs ywAtJATMdIL96fAFVAkMfrYJU5v5/Au2UGvBYD/r9b+wsFINI30v+KRArEZv8zy/ rPPZD0Iub3V7aTtsF6nwYyabPGZpSz3k4N7fBmlpFTZoCMqpVw5smXB8sSLPlx8h AcR8XroQz0D3 =YJyX -----END PGP SIGNATURE-----