-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 20 Mar 2026 14:55:53 +0100 Source: debsbom Architecture: source Version: 0.7.1-1 Distribution: unstable Urgency: medium Maintainer: Debian Python Team <team+python@tracker.debian.org> Changed-By: Felix Moessbauer <felix.moessbauer@siemens.com> Changes: debsbom (0.7.1-1) unstable; urgency=medium . * New upstream version 0.7.1 * Fix checksums of source packages not being properly compared * Make essential property for CDX SBOMs a string instead of a boolean * Emit stderr for subcommands errors for the merge command * Properly merge external references for CDX SBOMs * Correctly interpret and apply --sbom-type options for multiple commands * Also merge license information when merging CDX SBOMs Checksums-Sha1: 869dc8fbe281b45277b7a9e21c835385eaef143c 2732 debsbom_0.7.1-1.dsc 1290cb19c880eab08d99065102daa68dbfb6ed6e 152108 debsbom_0.7.1.orig.tar.xz 5f6cb2a9bb645cf07442f558154827baf751147d 8344 debsbom_0.7.1-1.debian.tar.xz e4f68da5dd2996fcc9c31c48aa391e498b554f33 9502 debsbom_0.7.1-1_amd64.buildinfo Checksums-Sha256: 30f26a1c5600cb727d1f3c9838e02fd428ff064d231c193d65d06891a09acad5 2732 debsbom_0.7.1-1.dsc 65ebb75218c944e2adc7af60c66d948dfba4b8a5520709107c3d016e01999bfc 152108 debsbom_0.7.1.orig.tar.xz 757bb934a684a1b081933788205f275fb67ad32aa223cddf8782496369a76181 8344 debsbom_0.7.1-1.debian.tar.xz 99ae61f6edfd3dcba4d0b9c7f523ad4414a7ca97170e0c1493bdc6303ffff6fa 9502 debsbom_0.7.1-1_amd64.buildinfo Files: c2ed82cdc790b56ce023575e2a70ec84 2732 python optional debsbom_0.7.1-1.dsc 06ecede5fc8a9b9764d910e7faecfe33 152108 python optional debsbom_0.7.1.orig.tar.xz 0ecb3b607f789b06a6d80ede42ee6406 8344 python optional debsbom_0.7.1-1.debian.tar.xz 5a323c863c692c2e709756af07a9af9e 9502 python optional debsbom_0.7.1-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQJRBAEBCgA7FiEEr3P271pTz+MEVp9Q5kijEfZ6UPwFAmm9U6AdHGZlbGl4Lm1v ZXNzYmF1ZXJAc2llbWVucy5jb20ACgkQ5kijEfZ6UPxkPg//QxRdoxSXd0c96BGu ySBHpNQ3tgHs6R0iT2V66KHWaYbCebr879wU9QSV2EY5iAOhmyP8P5rx23+d4lRW 0U88sz83+RRVqU/BoLau8JmAL56HAddnvf4S80Hymz5H21npEGHaZVZ8VJhbnMpI /cVd88rgm8tJXgX0RNuRqW4kInBnlDd+gg4rVIR3BqoUrTKxShvaiv2XPYSUEMZF iTSeg9fsoPslh7Uw2jT8kVFl+nxmk3ZQwtHzxsMJONHMt0+bo1EPJFQqIpU74ETd dsZg7NgT42R5Kmgazj22nta/9M+2GtCrNqNV59Q4vb1AaxI1Y/AaWkjkoLTsB4vT rPrXGEzIf8TtnDnOJ3Be06ViZ16UuY7pt3EkdVwzXkpsw9tFJtALZLLSNnkapk4o KGgz95SvQkO8lK4AKyKx/IBqMji3fu6PgJE+AItMZ+mmXHQpDQ/4yfAZ7TbpR2X6 wpXp6ywHgk8YF4riEIg4TG+lZm9NYj7fiCYVoFKgat2hzgtX+VrfljU5SOtqbkSc CBdn7D7o2u32gxcB25+SCVvnfgiTHYhGVTquA1oP+TlpXVe/gVXHN7rQ4JHdPbTy jiJ2qLsIkfXsuL4xmiDvIaZaOt67HGzG9WB2a/0ayEXD9n08DJNOzlCJ2VFHa6Ay mUNlhou0TCof6Iu60x+L+vzhwEU= =nW/m -----END PGP SIGNATURE-----