-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 14 Apr 2026 15:02:57 +0200 Source: golang-github-sigstore-cosign-v2 Architecture: source Version: 2.6.3-2 Distribution: unstable Urgency: medium Maintainer: Debian Go Packaging Team <team+pkg-go@tracker.debian.org> Changed-By: Simon Josefsson <simon@josefsson.org> Closes: 1133216 Changes: golang-github-sigstore-cosign-v2 (2.6.3-2) unstable; urgency=medium . * Use /v2 import path (Closes: #1133216) * Don't use DH_GOLANG_BUILDPKG . golang-github-sigstore-cosign-v2 (2.6.3-1) unstable; urgency=medium . * New upstream version - Fixes CVE-2026-39395 Checksums-Sha1: ca6135e3301e042ecc6f46b743614ddafbf32251 4378 golang-github-sigstore-cosign-v2_2.6.3-2.dsc daf0824907a57eae1a5d8f0d2ce3a129cf319efa 5280 golang-github-sigstore-cosign-v2_2.6.3-2.debian.tar.xz e6cfdc5b82a56f8a1c83dc2a052c8ddd6aed861e 2020276 golang-github-sigstore-cosign-v2_2.6.3-2.git.tar.xz 4c0f6279294d05e54c704e94c6697a9c732b815d 17434 golang-github-sigstore-cosign-v2_2.6.3-2_source.buildinfo 4514853a1257b434392ee8e6c008ff68c21a47e2 677432 golang-github-sigstore-cosign-v2_2.6.3.orig.tar.xz Checksums-Sha256: 43739916c7ce756d15b9aed4bfa3fdfcf91fcdee8fd46adae08ee804caf13ada 4378 golang-github-sigstore-cosign-v2_2.6.3-2.dsc 4feb480daffa169622e5b0dc77f84f53d4e57794d10921228211d34210332a4d 5280 golang-github-sigstore-cosign-v2_2.6.3-2.debian.tar.xz 0953e39cdbc5bc49c9cc705968e525747c3e2f822dd82dd2bccdf60bd6d81f87 2020276 golang-github-sigstore-cosign-v2_2.6.3-2.git.tar.xz d93a96f5c1c5ff6521f1ea1b0f2be3fe1d6958ca63835698f17bda03e0ea8ce0 17434 golang-github-sigstore-cosign-v2_2.6.3-2_source.buildinfo 46fd3c0695bc85f1992a6cbc0dff913ca5d2abc172de847929a9b42b865ee000 677432 golang-github-sigstore-cosign-v2_2.6.3.orig.tar.xz Files: 56579a227667632cd655004295f9fc50 4378 golang optional golang-github-sigstore-cosign-v2_2.6.3-2.dsc ffd565ce1caf64ae960458b86c3472a9 5280 golang optional golang-github-sigstore-cosign-v2_2.6.3-2.debian.tar.xz 4e8aa0fe467ad6f95453f0de61464311 2020276 golang None golang-github-sigstore-cosign-v2_2.6.3-2.git.tar.xz 9bea3aa41c58cd6ca8873d36975cbe2d 17434 golang optional golang-github-sigstore-cosign-v2_2.6.3-2_source.buildinfo 9b2af49901b7aa93d5a9d87a5dd1e43c 677432 golang optional golang-github-sigstore-cosign-v2_2.6.3.orig.tar.xz Git-Tag-Info: tag=5bd297429b9200accb4dffe2ac8b4a22a93e414d fp=a3cc9c870b9d310abad4cf2f51722b08fe4745a2 Git-Tag-Tagger: Simon Josefsson <simon@josefsson.org> -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmneQfoACgkQYG0ITkaD wHkMvBAA2PMwRWqa+UZDn2pvWtnisqs++fuiAfHKdHBHTfLHbFF3dZcE4lMcXLCg ROfsPzZzUlwALVUPmh5XoAYNrEDSWDcOxy7kp+KhnE7kAIUGyxIbpcR3/1Et6aub brYa22da/ciwIwJazXyUmjfrQWIr2wX1wlyjjxRaNme1u3iQuSsExtcAeXKotvIc l4Sw3ZtYnhRKCoDulgHu2oQ3gfpCs5QGS2RKdT13AzasrQh5r05isrZEoFGo2xSE 8hXCttM94hlyzt+v7ZS9Xmp5vMnj1X/T+e8fkCY4Tt46wIoN0KFk5AeapchMhEzt 5lSbeQ7X2n8MTP1DyRPl79qnF6C9Do0I2LqlJEl1V3slcMMibk2qz8DoUgxHYsug UKGbZaDJFPrDBU87O2B4MGJKbG5Z6g9Xa4P7vNrTucNqWbtDFoOpHYohVgfuWDl2 abYFUezXq2mNn6xO5mFampUUOOHux0PgqBdqMYbS2GQjMSI9dBgBD5JEKhOCyBJH rWi8b/DHtQTj9MxfEb+ReWJHE7h90P3kGSxlInu5HyQ7OuHbeXKNWIFK9dUz3rUJ RdR5hU8sAd++h7xsUAZ+W+nTx2BUc/AFwNetASVJqZVbZ5e2X77ajHmC0XZfS8FQ OaN71noW947RPOjiRHcQQKFGjnRqfdbUQsAt14soO5cFnx5M8+s= =E9++ -----END PGP SIGNATURE-----