-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 31 May 2025 12:52:39 -0400 Source: golang-github-notaryproject-notation-core-go Architecture: source Version: 1.1.0-7 Distribution: experimental Urgency: medium Maintainer: Debian Go Packaging Team <team+pkg-go@tracker.debian.org> Changed-By: Reinhard Tartler <siretart@tauware.de> Changes: golang-github-notaryproject-notation-core-go (1.1.0-7) experimental; urgency=medium . * fix: add tsa cert chain revocation check after timestamping (#246) Needed for CVE-2024-56138 Checksums-Sha1: cddc09ad80ffc384de330f1eed114cdf373d76be 2813 golang-github-notaryproject-notation-core-go_1.1.0-7.dsc e17f99dca3c14bcae2748561a76ece1d7310bf76 7656 golang-github-notaryproject-notation-core-go_1.1.0-7.debian.tar.xz Checksums-Sha256: 0a08cd6d76f08ae7f1e96851e674c6565b362d0771c4635efabf283b3f7da20f 2813 golang-github-notaryproject-notation-core-go_1.1.0-7.dsc cbb87279d0f94a5c9f55f0505888641377fb72b68c5f73f161eb27a50ff4d168 7656 golang-github-notaryproject-notation-core-go_1.1.0-7.debian.tar.xz Files: 25a6c818b6e016ce024c591c1814b6a1 2813 golang optional golang-github-notaryproject-notation-core-go_1.1.0-7.dsc 673cb0de24019ca9bd6ab430a547185c 7656 golang optional golang-github-notaryproject-notation-core-go_1.1.0-7.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQJHBAEBCgAyFiEEMN59F2OrlFLH4IJQSadpd5QoJssFAmg7NDwUHHNpcmV0YXJ0 QHRhdXdhcmUuZGUACgkQSadpd5QoJstiQA/4pyAL+ad9fOZ3hOXsSuOrPX385p7U XsU0OQNcO6QacphxLypyIDk+chtEcJ7GnWsA0mZa/oO0BVezNFhT3TNUqQvv3mpy O/WALN/RK6GjbRQPw488nGjcMmjMevVhpVvfnwZFs3KEghi5f/RhIgSFlJE5i4FM Ou4l9F48S/DjXKv7ICh1gzVdkYi8P6caUwk4OOW53Vnb4AtqGN9xECwEFwtQ0oAT SoFVLJ9e6VQhRyFpA5fVbClzYcbdJCoN3CxmpOENjkgatq50kDYgxqrYAJFS+SgV Mdu0O6QV+3h6ysNT2jPxLvhuW6RFfnq/tK8qvL0rAa2ROR+ByvQNKBkgOcT6p3Wp ARb2zKS+2JjmHBlQ/jdle4pQpl8hCBVYJxwimQGUkSNdSQvzOAkpdyMc70Du5KcB yocZUqfPzX2a+r04upF0iW0QcfPHOzIgAb2LhKG55MN4wxp0o26xLyYvcRJP7psz 4LVmSvnWo/bh7rDhrizGdN6B2FHp1EXZj0kBQHodjf7zEXEAWeqYDdRhp6c+yCa+ hsxckNp/2DWgDfS5gEy0O473Bk3gDNir5FJDbmP2iTN1ky++UBNE0ujd562IgDpn CfkY9rcaoVcdA+9pzmy1wzCOgA7TI9XK9kOyp7FZ7CGRD96Mg+Z2mUIDTWlEfRIp aSM4YXF5XaPDLA== =Jexz -----END PGP SIGNATURE-----