[Pkg-utopia-maintainers] flatpak_1.12.3-1_source.changes ACCEPTED into unstable

Debian FTP Masters ftpmaster at ftp-master.debian.org
Wed Jan 12 20:34:12 GMT 2022



Accepted:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Wed, 12 Jan 2022 13:33:12 +0000
Source: flatpak
Architecture: source
Version: 1.12.3-1
Distribution: unstable
Urgency: high
Maintainer: Utopia Maintenance Team <pkg-utopia-maintainers at lists.alioth.debian.org>
Changed-By: Simon McVittie <smcv at debian.org>
Changes:
 flatpak (1.12.3-1) unstable; urgency=high
 .
   * New upstream stable release
   * Security fixes:
     - Prevent a malicious repository from arranging for permissions to be
       granted without being correctly displayed during installation
       (CVE-2021-43860, GHSA-qpjc-vq3c-572j)
     - Prevent a malicious build in flatpak-builder creating directories
       outside the build directory (GHSA-8ch7-5j3h-g4fx)
   * Behaviour changes, as a result of how GHSA-8ch7-5j3h-g4fx was fixed:
     - --nofilesystem=host is now special-cased to negate all --filesystem
       permissions. Previously, it would cancel out --filesystem=host but
       not --filesystem=/some/dir.
     - --nofilesystem=home is now special-cased to negate several
       home-directory-related filesystem permssions such as
       --filesystem=xdg-config/foo, not just --filesystem=host.
   * Other bug fixes:
     - Extra-data downloading now properly handles compressed
       content-encodings, which fixes checksum verification
     - Avoid unnecessary polkit prompt due to auto-pinning when installing
       runtimes
     - Better handling of updates of extensions that exist in multiple
       repositories
     - Fixed (initial) installation of apps with renamed app-IDs
     - Support more pulseaudio configuration, including the one used in WSL2
     - Fixed regression in updates from no-enumerate remotes
     - We now verify checksums of summary caches, to better handle local file
       corruption
     - Improved CLI output for non-terminal targets
     - Flatpak run --session-bus now works
     - Fix build with PyParsing >= 3.0.4
     - bash auto completion now doesn't complete on command name aliases
     - Minor improvements to the search command
     - Minor improvements to the list command
     - Minor improvements to the repair command
     - Add more tests
     - Updated translations and docs
   * d/copyright: Update
Checksums-Sha1:
 48a06a8fbea43e4d64361f057a610fa6ece9fe0d 3633 flatpak_1.12.3-1.dsc
 c133c2ee8f2d7d54dbdfa8cde5bf46f0bd22696f 1555340 flatpak_1.12.3.orig.tar.xz
 3e7bb9f477550529a545bb88c6047c34f786559b 32900 flatpak_1.12.3-1.debian.tar.xz
 9775fa5326eaed5bae699641c46a8a88258f07b9 11943 flatpak_1.12.3-1_source.buildinfo
Checksums-Sha256:
 6fb864a8173454c529e68a500ba38f86d46e8c2f29c7412866fd1cc318c6174e 3633 flatpak_1.12.3-1.dsc
 d715f23347d7eb859301c8f0c778a899bb7c9e26dac6ae2a2a4b9fc21cf77b69 1555340 flatpak_1.12.3.orig.tar.xz
 3ff244f827c35fd00ee230765a5bdacefa6e31580bf937907c930183b65ed3b4 32900 flatpak_1.12.3-1.debian.tar.xz
 793030cc65d2aef48842c933a8358a4ccf425e18b59a8bd6d673e5dc02ee43de 11943 flatpak_1.12.3-1_source.buildinfo
Files:
 2b6cac2f0508d32afbc55d9055bf6384 3633 admin optional flatpak_1.12.3-1.dsc
 e6f467e59bc0147942645fc54b24a0ff 1555340 admin optional flatpak_1.12.3.orig.tar.xz
 6263d5bc501d312278262ecd09f510b3 32900 admin optional flatpak_1.12.3-1.debian.tar.xz
 7b3a0dbde4a4efec597a23a8ea7ac721 11943 admin optional flatpak_1.12.3-1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEENuxaZEik9e95vv6Y4FrhR4+BTE8FAmHfIyQACgkQ4FrhR4+B
TE+nKBAArnOQempjidvL/unLGfZecycrukg2bZ4oDhF2m3aFiGamNCVuP6bZqTRA
zTeY3BQHI5Ffau1RSFgrow1gtJoh3wnKkLopnwuKmrUpi+O+95WkjnjQZsvdjcRH
i6oAwgdKBLLb3ZiYJfKZHW39tEZknlLdJjYovZJnANQdEd7P8D5dDywRL5AjNVGO
03e/3lrKN4vxJrywO0kLv5ZpxRaWB1XtdDdg9of4MhteN2fXSDY1dj0gJw58LET8
txneVSwbYeRfcdhqhw5KovH7Kz1tsgyXeUqegvqAYOPZdOyhvf03c77K+N2q2EUg
XPhOu2Ntmcf1zCjNzVoYRRMGAwcUw6yBvp90IDJJud7Yo0nWhO0Gqrqh2RldNgHw
TFhunZIPdMzzDLdRXJkTwDezierd2d849iP0GuCJXis+N6eZ4tqdhBQSA4Yut0QG
R/DhQDsKzMXAAxjz4zlznnpqO5T3d0qvNNleALmcGszyNAMw32NeXR4IIZ5px5g6
7ezNDHg8m4btH8to/7WufNUhSndQXYwE2NX9o7UEFOx7LKNXCAuteqmErqUfqV2S
J3xChbrPa9v3F1O9NpAM6LDLzRDW4BQjf7xcK1/oHIx638LO+RoDpQJNULduNNyD
eYWG1FesCDe/KwKiFnvrTVYRfx4Xl20jfu8xnKXgcc3wJ7bYTeA=
=C0Ht
-----END PGP SIGNATURE-----


Thank you for your contribution to Debian.



More information about the Pkg-utopia-maintainers mailing list