Re: Fwd: dar_2.7.10-2~bpo12+1_amd64.changes REJECTED
On Tue, Aug 15 2023, Cyril Brulebois wrote:
> [[PGP Signed Part:Undecided]]
> John Goerzen <jgoerzen@complete.org> (2023-08-15):
>> Anybody have any ideas about this one? According to
>> packages.debian.org, that version of curl is indeed in bookworm. (Well,
>> bookworm-security)
>
> Main dak sees this:
>
> curl | 7.88.1-10 | stable | source, amd64, arm64, armel, armhf, i386,
> mips64el, mipsel, ppc64el, s390x
> curl | 7.88.1-10+deb12u2 | proposed-updates | source, amd64, arm64, armel,
> armhf, i386, mips64el, mipsel, ppc64el, s390x
>
> with 7.88.1-10+deb12u1, which isn't one of those two, only in
> bookworm-security (so on different dak instance), and doesn't + won't
> show up in proposed-updates eventually because there's already a newer
> version there (via #1042848).
Thanks. That's helpful... though I'm not quite sure what to do about
it in general. I mean, I can easily enough deal with it in this case,
but if there HADN'T been a newer one in proposed-updates, then I would
have been forced to build against a package with known security issues,
I suppose? (I imagine a backport of a package in bookworm-security
would be rejected for similar reasons).
- John
Reply to: