Debian Package Tracker
Register | Log in
Subscribe

singularity-container

container platform focused on supporting "Mobility of Compute"

Choose email to subscribe with

general
  • source: singularity-container (main)
  • version: 3.11.0+ds1-1
  • maintainer: Debian HPC Team (archive) (DMD)
  • uploaders: Benda Xu [DMD] – Mehdi Dogguy [DMD] – Yaroslav Halchenko [DMD] – Dmitry Smirnov [DMD]
  • arch: all any
  • std-ver: 4.6.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-bpo: 2.6.1-1~bpo9+2
  • unstable: 3.11.0+ds1-1
versioned links
  • 2.6.1-1~bpo9+2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.11.0+ds1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • golang-github-sylabs-singularity-dev
  • singularity-container
action needed
A new upstream version is available: 3.11.1 high
A new upstream version 3.11.1 is available, you should consider packaging it.
Created: 2023-03-16 Last update: 2023-03-23 08:09
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2022-23538: github.com/sylabs/scs-library-client is the Go client for the Singularity Container Services (SCS) Container Library Service. When the scs-library-client is used to pull a container image, with authentication, the HTTP Authorization header sent by the client to the library service may be incorrectly leaked to an S3 backing storage provider. This occurs in a specific flow, where the library service redirects the client to a backing S3 storage server, to perform a multi-part concurrent download. Depending on site configuration, the S3 service may be provided by a third party. An attacker with access to the S3 service may be able to extract user credentials, allowing them to impersonate the user. The vulnerable multi-part concurrent download flow, with redirect to S3, is only used when communicating with a Singularity Enterprise 1.x installation, or third party server implementing this flow. Interaction with Singularity Enterprise 2.x, and Singularity Container Services (cloud.sylabs.io), does not trigger the vulnerable flow. We encourage all users to update. Users who interact with a Singularity Enterprise 1.x installation, using a 3rd party S3 storage service, are advised to revoke and recreate their authentication tokens within Singularity Enterprise. There is no workaround available at this time.
Created: 2023-01-18 Last update: 2023-01-19 06:08
lintian reports 8 warnings normal
Lintian reports 8 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2022-10-13 Last update: 2023-03-23 08:05
debian/patches: 2 patches to forward upstream low

Among the 6 debian patches available in version 3.11.0+ds1-1 of the package, we noticed the following issues:

  • 2 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2023-03-04 07:36
testing migrations
  • excuses:
    • Migrates after: golang-github-felixge-httpsnoop, golang-github-gorilla-handlers, golang-github-safchain-ethtool
    • Migration status for singularity-container (- to 3.11.0+ds1-1): BLOCKED: Rejected/violates migration policy/introduces a regression
    • Issues preventing migration:
    • ∙ ∙ Updating singularity-container would introduce bugs in testing: #1029669
    • ∙ ∙ blocked by freeze: is not in testing
    • ∙ ∙ Too young, only 19 of 20 days old
    • ∙ ∙ Built-Using: singularity-container golang-github-felixge-httpsnoop
    • ∙ ∙ Built-Using: singularity-container golang-github-gorilla-handlers
    • ∙ ∙ Built-Using: singularity-container golang-github-safchain-ethtool
    • Additional info:
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/s/singularity-container.html
    • Not considered
news
[rss feed]
  • [2023-03-03] Accepted singularity-container 3.11.0+ds1-1 (source) into unstable (Nilesh Patra)
  • [2023-02-25] singularity-container REMOVED from testing (Debian testing watch)
  • [2022-10-18] singularity-container 3.10.3+ds1-1 MIGRATED to testing (Debian testing watch)
  • [2022-10-12] Accepted singularity-container 3.10.3+ds1-1 (source) into unstable (Nilesh Patra)
  • [2022-09-30] singularity-container 3.10.2+ds3-1 MIGRATED to testing (Debian testing watch)
  • [2022-09-25] Accepted singularity-container 3.10.2+ds3-1 (source) into unstable (Nilesh Patra)
  • [2022-08-10] singularity-container 3.10.2+ds2-3 MIGRATED to testing (Debian testing watch)
  • [2022-08-04] Accepted singularity-container 3.10.2+ds2-3 (source) into unstable (Nilesh Patra)
  • [2022-07-31] Accepted singularity-container 3.10.2+ds2-2 (source) into unstable (Nilesh Patra)
  • [2022-07-31] Accepted singularity-container 3.10.2+ds2-1 (source) into unstable (Nilesh Patra)
  • [2022-07-31] singularity-container 3.10.1+ds1-1 MIGRATED to testing (Debian testing watch)
  • [2022-07-24] Accepted singularity-container 3.10.1+ds1-1 (source) into unstable (Nilesh Patra)
  • [2022-06-26] singularity-container 3.10.0+ds2-3 MIGRATED to testing (Debian testing watch)
  • [2022-06-17] Accepted singularity-container 3.10.0+ds2-3 (source) into unstable (Nilesh Patra)
  • [2022-06-14] Accepted singularity-container 3.10.0+ds2-2 (source) into unstable (Nilesh Patra)
  • [2022-06-13] Accepted singularity-container 3.10.0+ds2-1 (source) into unstable (Nilesh Patra)
  • [2022-06-13] Accepted singularity-container 3.10.0+ds1-1 (source) into unstable (Nilesh Patra)
  • [2022-05-03] singularity-container 3.9.9+ds1-1 MIGRATED to testing (Debian testing watch)
  • [2022-04-27] Accepted singularity-container 3.9.9+ds1-1 (source) into unstable (Nilesh Patra)
  • [2022-04-21] singularity-container 3.9.8+ds1-1 MIGRATED to testing (Debian testing watch)
  • [2022-04-15] Accepted singularity-container 3.9.8+ds1-1 (source) into unstable (Nilesh Patra)
  • [2022-03-22] singularity-container 3.9.6+ds1-1 MIGRATED to testing (Debian testing watch)
  • [2022-03-16] Accepted singularity-container 3.9.6+ds1-1 (source) into unstable (Nilesh Patra)
  • [2022-03-01] singularity-container 3.9.5+ds1-3 MIGRATED to testing (Debian testing watch)
  • [2022-02-24] Accepted singularity-container 3.9.5+ds1-3 (source) into unstable (Nilesh Patra)
  • [2022-02-23] Accepted singularity-container 3.9.5+ds1-2 (source) into unstable (Andreas Tille)
  • [2022-02-20] Accepted singularity-container 3.9.5+ds1-1 (source) into experimental (Nilesh Patra)
  • [2022-02-19] Accepted singularity-container 3.9.4+ds2-1 (source) into experimental (Andreas Tille)
  • [2021-12-21] Accepted singularity-container 3.5.2+ds2-1 (source) into unstable (Benda Xu)
  • [2020-08-14] singularity-container REMOVED from testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 1
  • RC: 1
  • I&N: 0
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (0, 8)
  • buildd: logs, checks, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debian patches

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing