-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 25 Nov 2025 03:40:45 +0100 Source: r-cran-gh Architecture: source Version: 1.2.0-1+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: Debian R Packages Maintainers <r-pkg-team@alioth-lists.debian.net> Changed-By: Daniel Leidert <dleidert@debian.org> Closes: 1110481 Changes: r-cran-gh (1.2.0-1+deb11u1) bullseye-security; urgency=medium . * Non-maintainer upload by the Debian LTS team. * d/patches/CVE-2025-54956.patch: Add patch to fix CVE-2025-54956. - The HTTP response is delivered in a data structure that includes the Authorization header from the corresponding HTTP request (closes: #1110481). Checksums-Sha1: 3d61c091038d8a4be200ff016be94e674922ad65 2117 r-cran-gh_1.2.0-1+deb11u1.dsc bdcb30537711370d8e88c32fa57b45db9e30a256 43909 r-cran-gh_1.2.0.orig.tar.gz db40f9eae1a1cb0a3a6f6be618d7ba2ca6b6fde8 4124 r-cran-gh_1.2.0-1+deb11u1.debian.tar.xz 458f82f2716d3474827972606c68b16cbd0d68cf 11345 r-cran-gh_1.2.0-1+deb11u1_amd64.buildinfo Checksums-Sha256: ea05e3676710c6722db7611811ca095713fa7f5946860d4dfb188878639d721a 2117 r-cran-gh_1.2.0-1+deb11u1.dsc 2988440ed2ba4b241c8ffbafbfdad29493574980a9aeba210521dadda91f7eff 43909 r-cran-gh_1.2.0.orig.tar.gz b6bf757e7cbf68a064b236362f2c98157ac040d18a6ea60594902c811282dfdb 4124 r-cran-gh_1.2.0-1+deb11u1.debian.tar.xz 62155dec0b2ac32698cf708b8a0bf722f01a7c7991424b61dfea0421fb5c76a1 11345 r-cran-gh_1.2.0-1+deb11u1_amd64.buildinfo Files: df09743f76c88ca46169733c4ece2cc8 2117 gnu-r optional r-cran-gh_1.2.0-1+deb11u1.dsc 322e079572dca841e0e73811236a6a82 43909 gnu-r optional r-cran-gh_1.2.0.orig.tar.gz abaf65697ba230670eafd4553d30bc64 4124 gnu-r optional r-cran-gh_1.2.0-1+deb11u1.debian.tar.xz c839abfb20d90299f5b2fa7e204d5d36 11345 gnu-r optional r-cran-gh_1.2.0-1+deb11u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEvu1N7VVEpMA+KD3HS80FZ8KW0F0FAmklJOMACgkQS80FZ8KW 0F3VqxAAwd96JmYJ2ysKdLzCTUF7fFWg6Hs2Dt/fy+6IMLRfB4+VVUItZ3GaMHgt iHrADUPcK0cyHgPYDWLbIZgxWn9o4X0+3V7o0x8pSvEXUnqRmJiYKtUBkgQbG5U6 O8tc5eBNYW4kzeCmWhcmgATR8Ju4n2eI88riOytvwwMiyENoeTn5f+ODfkR1t1od HO6EnXgG4HgOt/l0O82cY/rFO5Mxk96iHZltnCFbOiAjnstjImRgim1Ew25Bt6A1 sxcOUHsHNKTN2E0aog50jqpPIXy7PqM+b064HD706x13RU/Jh7cq1jRRbrxKiqNB BVyx+SSoRay74wwVPhNBWn8g1u7OBQH8mwGgkAPRaVaKYVpH4O4buIsGJwcWSzJ4 4HJnB8r4IptLLVqmCfSL1nzSDXH6a08OQaDrqRcmssBS7wvKHKe1JkVbhilYznz3 5+tfvBQSf2tc4PspBMfcA/GaRJYMsPjNiGDklQX3red0ir/zJCjQKlLRhe/w5Ajl nrD6FPk1sqwLNx2IdIovqI3gSGYzjgutb+/mQK9f9+0expiXKs1Ug2T+Clh7qPrh xVwY1+yCEnWNIefVnFF/3LD6772YZIjiWOM47ViPCZimt1vyZpfHiGQKrZiMLcci /kOquvV9qYgIVPM6Sombh63bX5OdaBcvthQpgO+ivDEPvQ84cK4= =ejXV -----END PGP SIGNATURE-----