Debian Package Tracker
Register | Log in
Subscribe

watcher

Choose email to subscribe with

general
  • source: watcher (main)
  • version: 16.0.0-5
  • maintainer: Debian OpenStack (DMD)
  • uploaders: Michal Arbet [DMD] – Thomas Goirand [DMD]
  • arch: all
  • std-ver: 4.5.1
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 5.0.0-1
  • oldstable: 9.0.0-2
  • stable: 14.0.0-1+deb13u1
  • testing: 16.0.0-5
  • unstable: 16.0.0-5
versioned links
  • 5.0.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 9.0.0-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 14.0.0-1+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 16.0.0-5: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python3-watcher
  • watcher-api
  • watcher-applier
  • watcher-common
  • watcher-decision-engine
  • watcher-doc
action needed
Marked for autoremoval on 05 September due to httpcore, ipywidgets, node-playwright, node-vscode-lsp, node-yarnpkg, python-repoze.who, towncrier: #1135849, #1138720, #1141793, #1143321, #1143428, #1143694, #1144575, #1144608 high
Version 16.0.0-5 of watcher is marked for autoremoval from testing on Sat 05 Sep 2026. It depends (transitively) on httpcore, ipywidgets, node-playwright, node-vscode-lsp, node-yarnpkg, python-repoze.who, towncrier, affected by #1135849, #1138720, #1141793, #1143321, #1143428, #1143694, #1144575, #1144608. You should try to prevent the removal by fixing these RC bugs.
Created: 2026-08-01 Last update: 2026-08-24 03:04
A new upstream version is available: 16.0.1 high
A new upstream version 16.0.1 is available, you should consider packaging it.
Created: 2026-08-20 Last update: 2026-08-24 03:03
2 security issues in bullseye high

There are 2 open security issues in bullseye.

2 important issues:
  • CVE-2026-76878: In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false value removes the key and skips the branch that normally restricts results to the caller's project. A non-admin user with the reader role can list alarms from all projects, exposing alarm actions containing trust webhook URLs, Heat signal endpoints, project IDs, and user IDs. The parameter can also be combined with a foreign project_id to target a specific project's alarms. A related concern is that OpenStack Watcher does not apply authorization to its webhook trigger endpoint. Any authenticated user who learns an audit's webhook URL, for example from this leaked Aodh alarm metadata, can start an EVENT audit and its associated action plan regardless of their own project or role. The webhook endpoint has lacked policy enforcement since its introduction in the Ussuri release (Watcher 4.0.0).
  • TEMP-1111689-27EE99:
Created: 2025-08-21 Last update: 2026-08-22 04:50
2 security issues in bookworm high

There are 2 open security issues in bookworm.

1 important issue:
  • CVE-2026-76878: In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false value removes the key and skips the branch that normally restricts results to the caller's project. A non-admin user with the reader role can list alarms from all projects, exposing alarm actions containing trust webhook URLs, Heat signal endpoints, project IDs, and user IDs. The parameter can also be combined with a foreign project_id to target a specific project's alarms. A related concern is that OpenStack Watcher does not apply authorization to its webhook trigger endpoint. Any authenticated user who learns an audit's webhook URL, for example from this leaked Aodh alarm metadata, can start an EVENT audit and its associated action plan regardless of their own project or role. The webhook endpoint has lacked policy enforcement since its introduction in the Ussuri release (Watcher 4.0.0).
1 issue postponed or untriaged:
  • TEMP-1111689-27EE99: (needs triaging)
Created: 2026-08-20 Last update: 2026-08-22 04:50
Does not build reproducibly during testing normal
A package building reproducibly enables third parties to verify that the source matches the distributed binaries. It has been identified that this source package produced different results, failed to build or had other issues in a test environment. Please read about how to improve the situation!
Created: 2026-08-22 Last update: 2026-08-24 01:34
1 new commit since last upload, is it time to release? normal
vcswatch reports that this package seems to have new commits in its VCS but has not yet updated debian/changelog. You should consider updating the Debian changelog and uploading this new version into the archive.

Here are the relevant commit logs:
commit 179b84710eddbbc41b09abac5bc28df7beb53790
Author: Thomas Goirand <zigo@debian.org>
Date:   Wed Aug 12 10:14:45 2026 +0200

      * CVE-2026-76878 / OSSA-2026-036: Watcher webhook trigger endpoint does not
        enforce oslo.policy authorization. Any authenticated user who learns a
        Watcher audit webhook URL can POST to the webhook to trigger an
        administrator-owned EVENT audit and its associated action plan, regardless
        of the caller's project or role. The webhook endpoint has lacked policy
        enforcement since its introduction in the Ussuri release. Applied upstream
        patch: "Add policy enforcement to webhook trigger endpoint".
        (Closes: #1144880)


https://salsa.debian.org/api/v4/projects/openstack-team%2Fservices%2Fwatcher API request failed: 401 Unauthorized at /srv/qa.debian.org/data/vcswatch/vcswatch line 410.
Created: 2026-08-21 Last update: 2026-08-21 13:31
lintian reports 21 warnings normal
Lintian reports 21 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-08-20 Last update: 2026-08-20 12:18
RFP: There is a request to reintroduce this package. normal
The WNPP database contains an RFP (Request For Package) entry for this package. This is probably an error, as it has already been packaged. Please see bug number #1109559 for more information.
Created: 2025-07-20 Last update: 2025-07-20 07:02
Multiarch hinter reports 1 issue(s) low
There are issues with the multiarch metadata for this package.
  • watcher-doc could be marked Multi-Arch: foreign
Created: 2016-10-08 Last update: 2026-08-24 00:30
debian/patches: 2 patches to forward upstream low

Among the 5 debian patches available in version 16.0.0-5 of the package, we noticed the following issues:

  • 2 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-08-20 10:31
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.5.1).
Created: 2021-08-18 Last update: 2026-08-20 03:20
news
[rss feed]
  • [2026-08-22] watcher 16.0.0-5 MIGRATED to testing (Debian testing watch)
  • [2026-08-19] Accepted watcher 16.0.0-5 (source) into unstable (Thomas Goirand)
  • [2026-08-02] watcher 16.0.0-4 MIGRATED to testing (Debian testing watch)
  • [2026-07-28] Accepted watcher 16.0.0-4 (source) into unstable (Thomas Goirand)
  • [2026-07-13] watcher 16.0.0-3 MIGRATED to testing (Debian testing watch)
  • [2026-07-08] Accepted watcher 16.0.0-3 (source) into unstable (Thomas Goirand)
  • [2026-06-02] watcher 16.0.0-2 MIGRATED to testing (Debian testing watch)
  • [2026-05-27] Accepted watcher 16.0.0-2 (source) into unstable (Thomas Goirand)
  • [2026-04-07] watcher 16.0.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-01] Accepted watcher 16.0.0-1 (source) into unstable (Thomas Goirand)
  • [2026-03-27] Accepted watcher 16.0.0~rc1-4 (source) into unstable (Thomas Goirand)
  • [2026-03-18] Accepted watcher 16.0.0~rc1-3 (source) into experimental (Thomas Goirand)
  • [2026-03-13] Accepted watcher 16.0.0~rc1-2 (source) into experimental (Thomas Goirand)
  • [2026-03-13] Accepted watcher 16.0.0~rc1-1 (source) into experimental (Thomas Goirand)
  • [2026-02-17] watcher 15.0.0-3 MIGRATED to testing (Debian testing watch)
  • [2026-02-11] Accepted watcher 15.0.0-3 (source) into unstable (Thomas Goirand)
  • [2025-11-06] Accepted watcher 14.0.0-1+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Thomas Goirand)
  • [2025-10-30] watcher 15.0.0-2 MIGRATED to testing (Debian testing watch)
  • [2025-10-24] Accepted watcher 15.0.0-2 (source) into unstable (Thomas Goirand)
  • [2025-10-07] watcher 15.0.0-1 MIGRATED to testing (Debian testing watch)
  • [2025-10-01] Accepted watcher 15.0.0-1 (source) into unstable (Thomas Goirand)
  • [2025-09-30] Accepted watcher 15.0.0~rc1-2 (source) into unstable (Thomas Goirand)
  • [2025-09-16] Accepted watcher 15.0.0~rc1-1 (source) into experimental (Thomas Goirand)
  • [2025-08-23] watcher 14.0.0-3 MIGRATED to testing (Debian testing watch)
  • [2025-08-21] Accepted watcher 14.0.0-3 (source) into unstable (Thomas Goirand)
  • [2025-08-13] watcher 14.0.0-2 MIGRATED to testing (Debian testing watch)
  • [2025-07-11] Accepted watcher 14.0.0-2 (source) into unstable (Thomas Goirand)
  • [2025-04-07] watcher 14.0.0-1 MIGRATED to testing (Debian testing watch)
  • [2025-04-02] Accepted watcher 14.0.0-1 (source) into unstable (Thomas Goirand)
  • [2025-03-29] Accepted watcher 14.0.0~rc1-2 (source) into unstable (Thomas Goirand)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian (0, 21)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • l10n (-, 100)
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2:16.0.0-0ubuntu1
  • patches for 2:16.0.0-0ubuntu1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing