Debian Package Tracker
Register | Log in
Subscribe

rust-gix-url

Parse and serialize git URLs - Rust source code

Choose email to subscribe with

general
  • source: rust-gix-url (main)
  • version: 0.37.1-1
  • maintainer: Debian Rust Maintainers (archive) (DMD)
  • uploaders: Alexander Kjäll [DMD]
  • arch: any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • stable: 0.28.2-1
  • testing: 0.36.0-1
  • unstable: 0.37.1-1
versioned links
  • 0.28.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.36.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.37.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • librust-gix-url-dev
action needed
A new upstream version is available: 0.38.0 high
A new upstream version 0.38.0 is available, you should consider packaging it.
Created: 2026-08-26 Last update: 2026-09-05 17:30
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-82247: gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as terminating the authority component, contrary to RFC 3986. As a consequence, gix-transport's HTTP redirect identity guard (can_reuse_identity) compares the wrong host and fails open. An attacker controlling a redirect response can craft a Location header of the form <attacker-authority>?@<original-authority> so that gitoxide sends the caller's HTTP Basic Authorization credentials to an unintended host. gix-transport is affected in versions <= 0.49.0 (fixed in 0.58.1).
Created: 2026-08-29 Last update: 2026-09-01 22:00
The package has not entered testing even though the delay is over normal
The package has not entered testing even though the 2-day delay is over. Check why.
Created: 2026-08-30 Last update: 2026-09-05 21:02
1 low-priority security issue in trixie low

There is 1 open security issue in trixie.

1 issue left for the package maintainer to handle:
  • CVE-2026-82247: (needs triaging) gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as terminating the authority component, contrary to RFC 3986. As a consequence, gix-transport's HTTP redirect identity guard (can_reuse_identity) compares the wrong host and fails open. An attacker controlling a redirect response can craft a Location header of the form <attacker-authority>?@<original-authority> so that gitoxide sends the caller's HTTP Basic Authorization credentials to an unintended host. gix-transport is affected in versions <= 0.49.0 (fixed in 0.58.1).

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-08-29 Last update: 2026-09-01 22:00
testing migrations
  • excuses:
    • Migration status: Blocked. Can't migrate due to a non-migratable dependency. Check status below.
    • Blocked by: rust-gix
    • Migrates after: rust-gix-credentials, rust-gix-submodule, rust-gix-transport
    • Migration status for rust-gix-url (0.36.0-1 to 0.37.1-1): BLOCKED: Cannot migrate due to another item, which is blocked (please check which dependencies are stuck)
    • Issues preventing migration:
    • ∙ ∙ Implicit dependency: rust-gix-url rust-gix (not considered)
    • ∙ ∙ Invalidated by implicit-dependency
    • ∙ ∙ Implicit dependency: rust-gix-url rust-gix-credentials
    • ∙ ∙ Implicit dependency: rust-gix-url rust-gix-submodule
    • ∙ ∙ Implicit dependency: rust-gix-url rust-gix-transport
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/r/rust-gix-url.html
    • ∙ ∙ Autopkgtest for rust-gix-url/0.37.1-1: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, riscv64: Pass
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • ∙ ∙ Required age reduced by 3 days because of autopkgtest
    • ∙ ∙ 12 days old (needed 2 days)
    • Not considered
news
[rss feed]
  • [2026-08-24] Accepted rust-gix-url 0.37.1-1 (source) into unstable (Simon Quigley)
  • [2026-06-13] rust-gix-url 0.36.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-04] Accepted rust-gix-url 0.36.0-1 (source) into unstable (Alexander Kjäll) (signed by: capitol@debian.org)
  • [2026-02-24] rust-gix-url 0.32.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-02-14] Accepted rust-gix-url 0.32.0-1 (source) into unstable (Fabian Grünbichler) (signed by: Fabian Gruenbichler)
  • [2025-02-20] rust-gix-url 0.28.2-1 MIGRATED to testing (Debian testing watch)
  • [2025-02-14] Accepted rust-gix-url 0.28.2-1 (source) into unstable (Fabian Grünbichler)
  • [2024-10-27] rust-gix-url 0.27.4-1 MIGRATED to testing (Debian testing watch)
  • [2024-10-22] Accepted rust-gix-url 0.27.4-1 (source) into unstable (Fabian Grünbichler)
  • [2024-04-20] rust-gix-url 0.27.3-1 MIGRATED to testing (Debian testing watch)
  • [2024-04-16] Accepted rust-gix-url 0.27.3-1 (source) into unstable (Peter Michael Green)
  • [2023-12-16] rust-gix-url 0.25.1-1 MIGRATED to testing (Debian testing watch)
  • [2023-12-13] Accepted rust-gix-url 0.25.1-1 (amd64 source) into unstable (Debian FTP Masters) (signed by: Holger Levsen)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 0.32.0-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing