There is 1 open security issue in trixie.
There is 1 open security issue in sid.
Among the 138 debian patches available in version 3.2.3+dfsg2-17 of the package, we noticed the following issues:
commit eb9d82ff29c849eb5d0d0dbd1703072d3f0c20c3 Author: mirabilos <tg@debian.org> Date: Mon Aug 19 00:58:28 2024 +0200 adjust log levels for the new formatter (which will be merged from the rochade branch later) commit 483babc46872d25482216bad87f49f71e4f6c13a Author: mirabilos <tg@debian.org> Date: Sun Aug 18 18:42:02 2024 +0200 fix a CVE, while not relevant to us, the optimisation potential is commit ce9d97728d578448ca9a8f99d76383940600b10d Merge: bb284e10 0eae721f Author: mirabilos <tg@debian.org> Date: Mon Jul 8 22:54:45 2024 +0200 Merge branch 'gcc14' commit bb284e10fb5620ee16659a59ab2985c0024fbc2e Merge: 22c20950 b215de27 Author: mirabilos <tg@debian.org> Date: Mon Jul 8 19:55:41 2024 +0200 Merge branch 'rochade' commit b215de27f29077c3ee542b5256758550b7afa5b7 Author: mirabilos <tg@debian.org> Date: Mon Jul 8 19:55:11 2024 +0200 note © commit e15a55ee13fae35f879cb80973e231a2e5b3af87 Author: mirabilos <tg@debian.org> Date: Sun Aug 14 04:41:39 2022 +0200 cmake’s ctest can surprise with colour output :/ (cherry picked from commit 3469d57de96988a2e6e729588aa925e7985fcd0e) commit 22c20950ca8302ba9c531d09f61cad9a950a5ac3 Merge: 03cddcef 6ccad635 Author: mirabilos <tg@debian.org> Date: Mon Jul 8 19:50:23 2024 +0200 Merge branch 'rochade' commit 03cddcef7676bfca48a448dfb8a201b34812e5a2 Merge: c915dcac 0aaefca4 Author: mirabilos <tg@debian.org> Date: Mon Jul 8 19:22:40 2024 +0200 Merge branch 'gcc14' commit 6ccad635218bf700ba5dce261c91120fa2b5159d Author: mirabilos <tg@debian.org> Date: Mon Jul 8 19:09:00 2024 +0200 we’ll have to pull ahead a GCC 14 bugfix release first commit c915dcac8a28f98ed3ad007138952010a927b4c3 Merge: 1dfe6099 3372f811 Author: mirabilos <tg@debian.org> Date: Mon Jul 8 19:08:35 2024 +0200 Merge branch 'gcc14' commit ecc772136051a815c1b206cbe8a6872078ad5049 Author: mirabilos <tg@debian.org> Date: Sat Jun 29 13:18:44 2024 +0200 more rebranding seems to be going on… commit 4a0f61c7d51096df9d24dbdbeff0deb08f3b9678 Author: mirabilos <tg@debian.org> Date: Fri May 10 20:24:35 2024 +0200 add a security note that better not just be implicit commit 1dfe60991b866983ea3e67d5d7aea640db4cb897 Merge: e992e0a4 d32ad08d Author: mirabilos <tg@debian.org> Date: Sat May 4 23:47:42 2024 +0200 Merge branch 'rochade' commit d32ad08d635f42c6d52cc067dac9f3dd13e79ee6 Author: mirabilos <tg@debian.org> Date: Sat May 4 23:45:35 2024 +0200 fixes from master applicable here, too (could be that even more are, but I don’t have the bandwidth to look) commit e992e0a46a2342718419e0afcc842010f074b5e6 Author: mirabilos <tg@debian.org> Date: Sat May 4 23:42:40 2024 +0200 docuemnt changes so far commit 84bb95e5c49348c044c71690ca0718a8e6fa18f7 Author: mirabilos <tg@debian.org> Date: Sat May 4 23:10:58 2024 +0200 small tweak to reduce delta to musescore2 commit ef26fc4270232540471f1e764e2152cacb41acab Merge: 587c4186 0c13efbf Author: mirabilos <tg@debian.org> Date: Sat May 4 23:09:31 2024 +0200 Merge branch 'rochade' commit 0c13efbfe5c96dfe3325f5ca6030f67fadebba6b Author: mirabilos <tg@debian.org> Date: Sat May 4 23:09:03 2024 +0200 small tweak to reduce delta to musescore3 commit 587c41869796ab1819c367c4748c6854f1458d0a Merge: 30d19d6b 0ec826aa Author: mirabilos <tg@debian.org> Date: Sat May 4 23:05:08 2024 +0200 Merge branch 'rochade' commit 0ec826aad530fba2233f4163a59f3644503b5a52 Author: mirabilos <tg@debian.org> Date: Sat May 4 22:50:52 2024 +0200 update and complete commit 4940f98e91a4eb85affc79a3c352b08367de17b4 Author: mirabilos <tg@debian.org> Date: Sat May 4 22:38:48 2024 +0200 note down changes so far commit 7479d8aec52e96c5b61772b2be33a6ef77db5210 Author: mirabilos <tg@debian.org> Date: Sat May 4 22:23:54 2024 +0200 erase another uscan tmpfile commit 91ebc1150d56e9bc3c756c53eeeed6e673adb611 Author: mirabilos <tg@debian.org> Date: Sat May 4 21:25:42 2024 +0200 fix typo commit 89a68a066780c54de705d048027101d46b7d6f1c Author: mirabilos <tg@debian.org> Date: Sat May 4 21:22:52 2024 +0200 fix pasto commit 0bbfb72a072bbec9bab8fefdfba8b878e63b6e7e Author: mirabilos <tg@debian.org> Date: Sat May 4 21:05:09 2024 +0200 switch to mode=git, otherwise things get too tricky for uscan… for git, do not use --clamp-mtime, force --mtime to something sensible, here the annotated tag’s time if present and the commit’s otherwise, as they use lightweight tags mostly ☹ commit 3dc76fd53c48af8374b0db81f6e6944d62abf61a Author: mirabilos <tg@debian.org> Date: Sat May 4 18:24:40 2024 +0200 adjust for old vs new versions - drop Bug-Submit and related properties, no new bugreports accepted - drop MuseScore BVBA-related, it’s been sold out to Muse Group - Mu͒seScore Studio - drop tutorials link, which now has v4-only contents commit 8b2ceab815f538ee29b1e84d7de07c898a56be06 Author: mirabilos <tg@debian.org> Date: Sat May 4 18:18:32 2024 +0200 it is now Mu͒seScore Studio + plans for musescore-snapshot musescore.com is now Mu͒seScore Catalogue; the äpps are now Mu͒seScore Sheet Music for Android and iOS; all these by Muse Group (which is the new owner company) musescore-snapshot will be Mu͒seScore 3 Evolution, which is a fork (“3.7”) by developers of the former (pre-takeover) community, with user contributions (keeping Catalogue compatibility where possible) commit 61d7deb90419140ee8f3487bb17393446e8f363b Author: mirabilos <tg@debian.org> Date: Sat May 4 17:49:44 2024 +0200 better keep the patchlevel across the +dfsg repack bump makes it easier for humans to quickly check versions commit d2e036a2fa804819d8f34576ea18ebc1c23d4376 Author: mirabilos <tg@debian.org> Date: Wed Apr 17 21:31:50 2024 +0200 up to commit 30d19d6b1128e7e717d94a04b3d24ff52d0074e2 (master) commit 46bf45ac2ee29adf6f4c0fe0a2c0cff0c9eca227 Merge: aec4131c db23a6c5 Author: mirabilos <tg@debian.org> Date: Wed Apr 17 21:27:40 2024 +0200 Merge tag '2.3.2+dfsg5' into rochade musescore2_2.3.2+dfsg5.orig.tar.xz commit db23a6c570a1052971461ec1343f2ee7e1b98330 Author: mirabilos <tg@debian.org> Date: Wed Apr 17 21:27:16 2024 +0200 musescore2_2.3.2+dfsg5.orig.tar.xz commit aec4131c5eaee10b77a9bc883ecf91c9ca45139e Author: mirabilos <tg@debian.org> Date: Wed Apr 17 21:21:10 2024 +0200 exclude some prebuilt font files and bump repacksuffix: see commit cbab6282d73ffe9f09ae5df2d8c06250f4c16ca3 and following in master (musescore3 packaging) branch commit 30d19d6b1128e7e717d94a04b3d24ff52d0074e2 Author: mirabilos <tg@debian.org> Date: Wed Apr 17 21:15:34 2024 +0200 use subdirectory hierarchy under debian/regen/ for easy application commit eb828622f7014145d224bab60898967ba1a23f88 Author: mirabilos <tg@debian.org> Date: Wed Apr 17 21:12:06 2024 +0200 commit updated MuseJazzText.otf file preferred format to work with/source, cf. commit 379486e4 source: commit 9014df48742f442ce8c482cd2bb3fd29c49e7f50 upstream commit 14f125621151efc13676e356880b3040049c037f Author: mirabilos <tg@debian.org> Date: Wed Apr 17 21:11:08 2024 +0200 debian/regen/ will be the location for the new font files commit be248bdb063e6ffd020503ac7f3e0da99a6342f3 Merge: 565322f9 8086707b Author: mirabilos <tg@debian.org> Date: Wed Apr 17 21:08:26 2024 +0200 Merge tag '3.2.3+dfsg3' musescore3_3.2.3+dfsg3.orig.tar.xz commit 8086707bb9eb735c540a331f36933774404c7af1 Author: mirabilos <tg@debian.org> Date: Wed Apr 17 21:07:22 2024 +0200 musescore3_3.2.3+dfsg3.orig.tar.xz commit 565322f9bfcb0c1c555a9a0e89bf834ce44cdff0 Author: mirabilos <tg@debian.org> Date: Wed Apr 17 20:49:29 2024 +0200 also exclude MuseJazzText.otf: while “good” (see previous commit), we want to update it to the latest version to get back kerning lost during external foundry working, and it’s easier to just update all font binaries the same way commit cbab6282d73ffe9f09ae5df2d8c06250f4c16ca3 Author: mirabilos <tg@debian.org> Date: Wed Apr 17 20:47:57 2024 +0200 exclude some prebuilt font files and bump repacksuffix: there is sufficient evidence that the shipped files weren’t cleanly built from the sources, and we will want to rebuild all of them now anyway, and it’s much easier this way commit 379486e416931614efe9628ae4d067a3bed9e3f4 Author: mirabilos <tg@debian.org> Date: Tue Apr 16 18:22:51 2024 +0200 paste MuseJazz source situation resolution to 3.0.2+dfsg1-1 entry: this was discussed, at length, in https://musescore.org/en/node/277756 and IRL at FOSDEM; MuseJazz for 3.x is a new font, and MuseJazz Text is a mix of the old MuseJazz and the former and both were done by an external studio, which doesn’t use FontForge, and new versions¹ now just start from the .otf files, which are suitable enough ① we’ll probably want to backport 9014df48742f442ce8c482cd2bb3fd29c49e7f50 that fixes kerning in MuseJazzText, though it’s binary-only commit 4bed98c870ad37bfc68fb712c0ce4879d73019bf Author: mirabilos <tg@debian.org> Date: Mon Apr 15 22:07:20 2024 +0200 more to do… commit c4ad14816b22fbee79b9df444c3423c286d3aa4f Author: mirabilos <tg@debian.org> Date: Mon Apr 15 22:04:12 2024 +0200 more to do… commit e893a6f0016e10ae7b2cab15504e36c536e82018 Author: mirabilos <tg@debian.org> Date: Mon Apr 15 22:01:32 2024 +0200 third truckload (as TODO), seems to be only one but huge commit commit 3008cd848064440bffa89a81345fcf2518012f41 Author: mirabilos <tg@debian.org> Date: Mon Apr 15 21:58:22 2024 +0200 add about two truckloads of backports, with one more to come commit afbaafcd4f37a27efb99805d590f05958df1ce87 Author: mirabilos <tg@debian.org> Date: Mon Apr 15 14:41:00 2024 +0200 more repo/branch planning commit 6ee048a836dd739f8d13aa2f3734c09e8c0b869e Author: mirabilos <tg@debian.org> Date: Mon Apr 15 14:30:50 2024 +0200 committed commit 07a054607c34cf87bac960447c7d7f2442a4d718 Author: mirabilos <tg@debian.org> Date: Mon Apr 15 14:12:06 2024 +0200 bit of release/branch planning commit 7b500ff43bf9e2450057a896a7ee26a66af35795 Author: mirabilos <tg@debian.org> Date: Wed Feb 7 16:45:51 2024 +0100 more branch split considerations commit 150e287524d5e95680fd774ce0561823d0a80197 Author: mirabilos <tg@debian.org> Date: Wed Feb 7 16:44:18 2024 +0100 oops commit e4dda66c804c5f3a85dd34ea78ac4ad554ed0447 Author: mirabilos <tg@debian.org> Date: Wed Feb 7 16:42:08 2024 +0100 gcc on focal/riscv64 crashes on this (jammy is ok) commit d1ef7332083c9575bbd93a8f44faf4a362351f8b Author: mirabilos <tg@debian.org> Date: Wed Feb 7 15:40:45 2024 +0100 omit git-repo-specific file from .debian.tar.gz commit efea5ab4e02cc2c4f1c9a55a544e2f537d6d6fde Author: mirabilos <tg@debian.org> Date: Wed Feb 7 15:38:58 2024 +0100 bring some order into the git branches commit 49c5ccdc892e63cca894338cbf96b897df229e2a Merge: 4cecfe0f 0906a66c Author: mirabilos <tg@debian.org> Date: Wed Oct 11 01:23:03 2023 +0200 Merge branch 'rochade' commit 0906a66c80075e1d23f21a21118c6fc27f941871 Author: mirabilos <tg@debian.org> Date: Wed Oct 11 01:22:52 2023 +0200 fix binfile output commit 4cecfe0ff5765dbf38d2127110911ffa1102271d Merge: 07f9deec 094f7033 Author: mirabilos <tg@debian.org> Date: Sun Oct 1 01:37:02 2023 +0200 Merge branch 'rochade' commit 094f7033f4a09318f6313a72fed125884dec7adb Author: mirabilos <tg@debian.org> Date: Sun Oct 1 01:25:42 2023 +0200 update d/watch and redo d/repack based on polyphone’s commit 85145531fe6d603486eb60c24be112afd17bcaef Author: mirabilos <tg@debian.org> Date: Sun Oct 1 01:23:57 2023 +0200 mu͒4 update commit 07f9deecac2384913656242a0a7779cd22565e72 Author: mirabilos <tg@debian.org> Date: Sat Sep 30 23:17:06 2023 +0200 fix obtaining prereleases, work around GitHub bug, make reusable commit 32345739f77d7e8d5082b034a4cd39799ac8c015 Author: mirabilos <tg@debian.org> Date: Sat Sep 30 22:29:26 2023 +0200 reindent (no change)
There is 1 open security issue in bookworm.