Debian Package Tracker
Register | Log in
Subscribe

golang-github-notaryproject-notation-go

Sign and verify OCI artifacts (library)

Choose email to subscribe with

general
  • source: golang-github-notaryproject-notation-go (main)
  • version: 1.2.1-4
  • maintainer: Debian Go Packaging Team (DMD)
  • uploaders: Reinhard Tartler [DMD]
  • arch: all
  • std-ver: 4.7.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • testing: 1.2.1-4
  • unstable: 1.2.1-4
  • exp: 1.2.1-5
versioned links
  • 1.2.1-4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.2.1-5: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • golang-github-notaryproject-notation-go-dev
action needed
Marked for autoremoval on 06 July: #1094409 high
Version 1.2.1-4 of golang-github-notaryproject-notation-go is marked for autoremoval from testing on Sun 06 Jul 2025. It is affected by #1094409. The removal of golang-github-notaryproject-notation-go will also cause the removal of (transitive) reverse dependency: golang-github-notaryproject-notation. You should try to prevent the removal by fixing these RC bugs.
Created: 2025-04-24 Last update: 2025-06-09 00:04
A new upstream version is available: 1.3.2 high
A new upstream version 1.3.2 is available, you should consider packaging it.
Created: 2024-12-18 Last update: 2025-06-08 23:56
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2024-56138: notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications. This issue was identified during Quarkslab's audit of the timestamp feature. During the timestamp signature generation, the revocation status of the certificate(s) used to generate the timestamp signature was not verified. During timestamp signature generation, notation-go did not check the revocation status of the certificate chain used by the TSA. This oversight creates a vulnerability that could be exploited through a Man-in-The-Middle attack. An attacker could potentially use a compromised, intermediate, or revoked leaf certificate to generate a malicious countersignature, which would then be accepted and stored by `notation`. This could lead to denial of service scenarios, particularly in CI/CD environments during signature verification processes because timestamp signature would fail due to the presence of a revoked certificate(s) potentially disrupting operations. This issue has been addressed in release version 1.3.0-rc.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Created: 2025-01-21 Last update: 2025-06-04 03:35
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2024-56138: notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications. This issue was identified during Quarkslab's audit of the timestamp feature. During the timestamp signature generation, the revocation status of the certificate(s) used to generate the timestamp signature was not verified. During timestamp signature generation, notation-go did not check the revocation status of the certificate chain used by the TSA. This oversight creates a vulnerability that could be exploited through a Man-in-The-Middle attack. An attacker could potentially use a compromised, intermediate, or revoked leaf certificate to generate a malicious countersignature, which would then be accepted and stored by `notation`. This could lead to denial of service scenarios, particularly in CI/CD environments during signature verification processes because timestamp signature would fail due to the presence of a revoked certificate(s) potentially disrupting operations. This issue has been addressed in release version 1.3.0-rc.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Created: 2025-01-21 Last update: 2025-06-04 03:35
4 new commits since last upload, is it time to release? normal
vcswatch reports that this package seems to have new commits in its VCS but has not yet updated debian/changelog. You should consider updating the Debian changelog and uploading this new version into the archive.

Here are the relevant commit logs:
commit a6d47155e275ff531aaa237c885196bf74c90c18
Author: Reinhard Tartler <siretart@tauware.de>
Date:   Sun Jun 1 08:32:04 2025 -0400

    Also tighten dependends for the -dev package

commit ec347bd48f60727567b3c436768973ed2889190b
Author: Reinhard Tartler <siretart@tauware.de>
Date:   Sat May 31 12:48:49 2025 -0400

    Update changelog for 1.2.1-5 release

commit 6713dc906801d33ea9d000f5995a16d7c4ff46f2
Author: Reinhard Tartler <siretart@tauware.de>
Date:   Sat May 31 12:47:54 2025 -0400

    Bump dependency on golang-github-notaryproject-notation-core-go-dev

commit dcfd6218cd20a5294b67282176a8acb9c06de292
Author: Reinhard Tartler <siretart@tauware.de>
Date:   Sat May 31 12:10:23 2025 -0400

    fix: enable timestamping cert chain revocation check during signing (#482)
    
    Signed-off-by: Patrick Zheng <patrickzheng@microsoft.com>
Created: 2025-06-01 Last update: 2025-06-01 16:51
lintian reports 1 warning normal
Lintian reports 1 warning about this package. You should make the package lintian clean getting rid of them.
Created: 2025-05-15 Last update: 2025-05-15 08:32
debian/patches: 3 patches to forward upstream low

Among the 4 debian patches available in version 1.2.1-4 of the package, we noticed the following issues:

  • 3 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2024-12-18 Last update: 2025-05-15 08:34
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.2 instead of 4.7.0).
Created: 2025-02-21 Last update: 2025-05-15 08:01
news
[rss feed]
  • [2025-06-04] golang-github-notaryproject-notation-go 1.2.1-4 MIGRATED to testing (Debian testing watch)
  • [2025-06-01] Accepted golang-github-notaryproject-notation-go 1.2.1-5 (source) into experimental (Reinhard Tartler)
  • [2025-05-14] Accepted golang-github-notaryproject-notation-go 1.2.1-4 (source) into unstable (Santiago Vila)
  • [2024-12-31] golang-github-notaryproject-notation-go 1.2.1-3 MIGRATED to testing (Debian testing watch)
  • [2024-12-27] Accepted golang-github-notaryproject-notation-go 1.2.1-3 (source) into unstable (Reinhard Tartler)
  • [2024-12-26] Accepted golang-github-notaryproject-notation-go 1.2.1-2 (source) into unstable (Reinhard Tartler)
  • [2024-12-17] Accepted golang-github-notaryproject-notation-go 1.2.1-1 (all source) into unstable (Debian FTP Masters) (signed by: Reinhard Tartler)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian (0, 1)
  • buildd: logs, exp, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.2.1-4

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing