There are 31 open security issues in bullseye.
There are 23 open security issues in buster.
commit ebebe1d25a9709058cbf9530d669d8807812b147
Author: Andreas Dolp <dev@andreas-dolp.de>
Date: Tue Feb 10 18:51:36 2026 +0100
d/p/fix-repeated-builds.patch: Add headers with more infos about the patch
commit 899b42dc3f78619272a1dac8d4710461459f39c3
Author: Andreas Dolp <dev@andreas-dolp.de>
Date: Sun Feb 8 14:17:39 2026 +0100
d/p/cross.patch: Add headers with more infos about the patch
Not applying the patch results in the lintian warning described.
commit a347506a3c2440ec6271f15b833c753159a49224
Author: Andreas Dolp <dev@andreas-dolp.de>
Date: Thu Jan 22 23:36:36 2026 +0100
d/p/with-ebpf-includes.patch: Add headers with more infos about the patch
commit f7a885a8bf8b1c2019329a88ede45977138fa0ca
Author: Andreas Dolp <dev@andreas-dolp.de>
Date: Thu Jan 22 21:08:05 2026 +0100
d/p/no-use-gnu.patch: Add headers with more infos about the patch
commit 4a900fde1a67371f437d4321ceee4273de5ce302
Author: Andreas Dolp <dev@andreas-dolp.de>
Date: Sun Feb 8 16:19:55 2026 +0100
d/p/import-sockio-h.patch: Remove obsolete patch
This patch is taken from upstream commit b37554 [1], which is part
of Suricata >= 5.x. Thus the patch can be considered obselete because
it adds the include block a second time.
[1] https://github.com/OISF/suricata/commit/b37554e0bc3cf383e6547c5c6a69c6f6849c09e3.patch
commit efbc04550793a1d8e71f05ae4f897e61bf960d1a
Author: Andreas Dolp <dev@andreas-dolp.de>
Date: Sun Feb 8 15:35:51 2026 +0100
d/p/llc.patch: Remove obsolete patch
This patch fixed a bug during builds with new Debian clang 10
versions, where the output of 'clang --version' changed from
clang version 9.0.1-15+b1
to
Debian clang version 10.0.1-8+b1
which causes the parsing to fail.
This was fixed in an upstream patch by commit 37b1595c [1], so the
current Debian patch can be considered obsolete now.
[1] https://github.com/OISF/suricata/commit/37b1595c20959353ec438860dc5a49bcae227aa8.patch
commit d36075131e78153921098f1632321198ecf65e9b
Author: Andreas Dolp <dev@andreas-dolp.de>
Date: Mon Feb 2 19:48:27 2026 +0100
d/p/reproducible.patch: Remove obsolete patch
Tested multiple builds and suricata does build reproducible even
without this patch. The sha256sum of the binaries are identical,
so this patch is obsolete now.
commit 29d7fb03294a3322272397ffe18022e80b0a2dec
Author: Andreas Dolp <dev@andreas-dolp.de>
Date: Thu Jan 22 21:09:02 2026 +0100
d/p/configure-clang-variable.patch: Remove obsolete patch
This patch was introduced in a6830e69.
It was forwarded to upstream in a Github PR [1]. After some improvements
in [2] it was finally merged in [3].
The code added by configure-clang-variable.patch matches the code in
[1], so the patch is the first version of the upstream PR.
Because the improved version of the upstream PR [2] was accepted
upstream, the code is already present in configure.ac. Therefore the
patch is obsolete.
'suricata --build-info' is identical with and without the patch.
[1] https://github.com/OISF/suricata/pull/3674
[2] https://github.com/OISF/suricata/pull/4072
[3] https://github.com/OISF/suricata/pull/4112
commit d1aec88a4c821f49bd4b171a3e7e278c91685676
Author: Andreas Dolp <dev@andreas-dolp.de>
Date: Tue Feb 3 20:02:13 2026 +0100
d/salsa-ci.yml: Enable reprotest
commit 9eeabb8eb07c464a997e142fff392b850e3103b2
Author: Sascha Steinbiss <satta@debian.org>
Date: Fri Jan 30 10:56:59 2026 +0100
update changelog
commit e28fa56eda4e8c623ccc2a45d8f598ab8afc8065
Author: Sascha Steinbiss <satta@debian.org>
Date: Fri Jan 30 10:52:40 2026 +0100
set myself as Maintainer
commit 5af317c1b6e95da1973bc4e81b8357013c97971f
Author: Andreas Dolp <dev@andreas-dolp.de>
Date: Tue Jan 27 07:18:51 2026 +0100
d/suricata.logrotate: use 'create' instead of 'copytruncate'
This reverts da1c3c6d which was applied as a bugfix for #842049.
This is fixed upstream since suricata 3.2 [1] [2].
We should get back to 'create' instead of 'copytruncate' to stick
close to the upstream recommendations and because there could be some
'very small time slice between copying the file and truncating it, so
some logging data might be lost' when using 'copytruncate' [3].
[1] https://redmine.openinfosecfoundation.org/issues/1938
[2] https://github.com/inliniac/suricata/pull/2401
[3] https://manpages.debian.org/unstable/logrotate/logrotate.8.en.html#copytruncate
commit 312da107b9cd09948ad1635bd5362611d4f08d78
Author: Andreas Dolp <dev@andreas-dolp.de>
Date: Tue Jan 27 07:09:07 2026 +0100
Do not fail logrotate because of missing pid-file when suricata is not running
Closes: #1126405
commit e642990866b0d0ebfd4a13b7f338480acacbc2d7
Author: Andreas Dolp <dev@andreas-dolp.de>
Date: Tue Jan 27 06:45:37 2026 +0100
d/suricata.README.Debian: Fix paths to current locations
There are 5 open security issues in trixie.
You can find information about how to handle these issues in the security team's documentation.
There are 37 open security issues in bookworm.
You can find information about how to handle these issues in the security team's documentation.
Among the 12 debian patches available in version 1:8.0.3-1 of the package, we noticed the following issues: