-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sat, 07 Mar 2026 09:12:47 -0800
Source: golang-1.25
Architecture: source
Version: 1.25.8-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Go Compiler Team <team+go-compiler@tracker.debian.org>
Changed-By: Tianon Gravi <tianon@debian.org>
Changes:
golang-1.25 (1.25.8-1) unstable; urgency=medium
.
* Update to 1.25.8 upstream release
https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk/m/41DopX_WAAAJ
- CVE-2026-27142: html/template: URLs in meta content attribute actions
are not escaped
- CVE-2026-25679: net/url: reject IPv6 literal not at start of host
- CVE-2026-27139: os: FileInfo can escape from a Root
(notably, CVE-2026-27137 and CVE-2026-27138 apply only to 1.26+)
* Drop 0004-Replace-localhostCert-and-localhostKey.patch (obsolete via
https://github.com/golang/go/commit/0c56fa28180c1281bb4934bb6779a72a3fb43f52)
Checksums-Sha1:
f9f2025eaa8872e9b8e0f87c2683cb1f654c0028 2923 golang-1.25_1.25.8-1.dsc
1a048fd02de34b267f8c27c0030b36d1bd409e79 31991986 golang-1.25_1.25.8.orig.tar.gz
f7fcc88527cf64d470b5d9a6bf74e6bc5630796a 833 golang-1.25_1.25.8.orig.tar.gz.asc
1284178ce6a5ea03fdbd9569ebd81154144b3f1d 45920 golang-1.25_1.25.8-1.debian.tar.xz
1c4b796f3f2c12591a6e02431f204450b45983d4 5482 golang-1.25_1.25.8-1_source.buildinfo
Checksums-Sha256:
6114cbd685b3bc79a0203f2939a2c35a4f2974cc786247a0e0204c7dd14be203 2923 golang-1.25_1.25.8-1.dsc
e988d4a2446ac7fe3f6daa089a58e9936a52a381355adec1c8983230a8d6c59e 31991986 golang-1.25_1.25.8.orig.tar.gz
a0e3c824b496f280df9d49e66563b6969a6ba93a0fa8b0028a7df7805312fce1 833 golang-1.25_1.25.8.orig.tar.gz.asc
4ddad753c9ed3df8df9ec00e53ad9e295da77e1fff9fc8c59585d2895ce4ffd3 45920 golang-1.25_1.25.8-1.debian.tar.xz
3f1d5855431b41daad8c227098473865adc8e423a5d8293925affff5bd4244ab 5482 golang-1.25_1.25.8-1_source.buildinfo
Files:
a6a4c9acf4a2e0c1b596ed3de35ed40c 2923 golang optional golang-1.25_1.25.8-1.dsc
6bff035aba352c8bc5275b00173ed8e2 31991986 golang optional golang-1.25_1.25.8.orig.tar.gz
e022b2735f79ffff5ca8473fdd5b2d80 833 golang optional golang-1.25_1.25.8.orig.tar.gz.asc
7e04e5cac65d94ee8dd8fdf977d69104 45920 golang optional golang-1.25_1.25.8-1.debian.tar.xz
d2dd59c9f9346328eead0bed2f7c54e9 5482 golang optional golang-1.25_1.25.8-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJGBAEBCgAwFiEEtC9oGQB/APiONk/UA2qcJb81fdQFAmmsXPcSHHRpYW5vbkBk
ZWJpYW4ub3JnAAoJEANqnCW/NX3Uz3wP/AyDXIUm+AVuIZup6mMmgLt2ZpUFedAD
uTPRbbLhwF8yJWOt47HXJNNf5rtfJgl0ahehTC7FZucyrh0uLoB2YPZKeXRPk5SS
+00RHE37L1xV8VB2EjA5zjQHIn+2IpIEJncnNUKJaoQj2K43FIha4cyBUZ1UHHO4
1ZTEBuvBS+HeNJJHcIQeBcRYz62pQ5/q0FJ/LBnnfAt1JyhzDKqSzqqvWfVCR7pv
br84t3QKzsRS/AYJA4hQOxK0xJdFbLVmGHluJpfcUg+5cCzmtAgZ+beG0YqGPtSC
O01EpmF5/m80y5uIdvHm8wx39SL+30Aq/X80YKiN2yt3l21govrI9tc4/ypIfEwo
q+cDpJxT3nDNhjR6Q4tljNH2kH4glqXmI7w3Nqkw6sRqc/iCkOhOQiIwUtTJsujQ
gv0HfabxCm4UdgZN0kF8o87ygnucgApyuBAw69wxbcwOKAPNkaT9q4XE3JpeRk0Z
uYnUYc0MYxyDhoTH1yBzPM8TkPM+F8F6z2HecmvxeV+1ckn2BiKev3Ky4Nqk330Q
tjNL8RVL4SW8RAbKGGnNVHXd89nwNucmzLjcd/lVr62MIgX7VdQhCdx9eOy9zKK+
aaT1f53QsDGSYvseX6ZNIcOaO2tmCRodlxc7aWI/9qMIMZPkNu9DvKnIY+I2pBd1
6nqZVpIzPZIb
=Ib11
-----END PGP SIGNATURE-----