-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 29 May 2026 17:39:31 +0200 Source: debsbom Architecture: source Version: 0.8.1-1~bpo13+1 Distribution: trixie-backports Urgency: medium Maintainer: Debian Python Team <team+python@tracker.debian.org> Changed-By: Felix Moessbauer <felix.moessbauer@siemens.com> Changes: debsbom (0.8.1-1~bpo13+1) trixie-backports; urgency=medium . * Fix a crash with packageurl-python versions <=0.17.0 when resolving packages * Add sec-scan command to find vulnerabilities in SBOM packages * Emit Static-Built-Using dependencies for packages * debian: remove cyclonedx from build dependencies * debian: add additional autopkgtest dependencies * New upstream version 0.8.1 Checksums-Sha1: cb3afcd3f2e9d398f8a1fa4d5b2aac1a863f878a 2730 debsbom_0.8.1-1~bpo13+1.dsc db9dbd48489fb5a63972f80f33242687625a528f 166264 debsbom_0.8.1.orig.tar.xz bbddfecdbcc09c74f52e31075d94240d1bb28620 8664 debsbom_0.8.1-1~bpo13+1.debian.tar.xz b119b87811658d9652786f6c4cb7b4da74088bad 9546 debsbom_0.8.1-1~bpo13+1_amd64.buildinfo Checksums-Sha256: 66ff6f3f71d979860967e11854e0fd8d7e2a7c8849f0fbaba0ca39718c62a96e 2730 debsbom_0.8.1-1~bpo13+1.dsc 9dd9328a5926b47d5714789751b3c6747ae5e6c7decbc975a088346c9adaaa26 166264 debsbom_0.8.1.orig.tar.xz 2b11d7281e2652d60c367cb1d87b812b0b5fc676c10d54d9cd8f232b9ef079a8 8664 debsbom_0.8.1-1~bpo13+1.debian.tar.xz 3f54a1e9c186aebb2fbc4d7f991d78016e8850e814a08328dc93e60e7efcfb42 9546 debsbom_0.8.1-1~bpo13+1_amd64.buildinfo Files: 442eb1a0a942b60dde25082c9da46d52 2730 python optional debsbom_0.8.1-1~bpo13+1.dsc 04dc74bfcb2d6995d2ba190474185689 166264 python optional debsbom_0.8.1.orig.tar.xz ab7748cfc16cc1f991c3a453ed382ec9 8664 python optional debsbom_0.8.1-1~bpo13+1.debian.tar.xz ae9b9e8f828b20b7ee5ccf6542bb9209 9546 python optional debsbom_0.8.1-1~bpo13+1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQJRBAEBCgA7FiEEr3P271pTz+MEVp9Q5kijEfZ6UPwFAmoZ7acdHGZlbGl4Lm1v ZXNzYmF1ZXJAc2llbWVucy5jb20ACgkQ5kijEfZ6UPwfug//WT4OCHzopyMLMjXw WHrySu9Mav6Trxr6kRR9XMGn+G1K6EmrVDJ3UVxH/mdaHZeVZ9bSB9eSZ402Yozq 7KeQ2S6rn/JaMd/JEaKwHwQrAnmtjlvJehI9A4MP8EqN0YStd74+t2VBwem/T/zR PbfQphUnzx0mAIUYEEMRo0VoA92/JygFupAOpT2CvU4jCpmSoPQghov6TiKdAsLP NmNu2LWMNHQdAcAJepdYxPw4DfVYPY0hzp7gCw5j7YJmxKWm8cxIsC+kCSlvoswy Pl9BOpQNgoefSlVP/8+cbWs+7NiVidqMtUHPuU02BNK1FfaDxcFrbqEZ2iTYwjoa 4nNKJ0tWgZKIQd7+/uqdGZ2G/8A0G1NLxaw15DY3L6XJsatPzOHuzctb0U52oTYS A9wCQHQhnAY1oomkEtz61kTrPZaeq1NrxOaX0x/R1CMzF9vCMr+n+/kOX5AZd3ws vjefObIF7TbC8Njj5+QA3a96yfHtMdo1fcyAs+iWSJShn4THMawYOHdSWwxIyuou 4ioZbxW5Ts/697u1Jgf4vSET4ZtIjq1LwwsNzZWsAS0JCisRAiJKjVJQ+lmA98mg hRJDITecXjrk0A9Ol6jSKcEXVIjrP/ymNBqvJ3Mwsx/r2bc6/6tFFW+sOmlY99Go j5gx7A484t4OQfJDxq6Z9mjZdcE= =kzJU -----END PGP SIGNATURE-----