Version 5.14.1+dfsg-1 of pagure is marked for autoremoval from testing on Sun 09 Mar 2025. It depends (transitively) on python-dom-toml, affected by #1094039. You should try to prevent the removal by fixing these RC bugs.
debian/patches: 3 patches with invalid metadata, 4 patches to forward upstream
high
Among the 36 debian patches
available in version 5.14.1+dfsg-3 of the package,
we noticed the following issues:
3 patches with
invalid metadata that ought to be fixed.
4 patches
where the metadata indicates that the patch has not yet been forwarded
upstream. You should either forward the patch upstream or update the
metadata to document its real status.
CVE-2024-47515:
A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the disclosure of local files. This flaw allows a malicious user to take advantage of the Pagure instance.
CVE-2024-47515:
A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the disclosure of local files. This flaw allows a malicious user to take advantage of the Pagure instance.