[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#855320: marked as done (developers-reference: Please do not recommend debrsign)



Your message dated Sun, 17 Feb 2019 13:34:11 +0000
with message-id <E1gvMaB-0005lf-Js@fasolo.debian.org>
and subject line Bug#855320: fixed in developers-reference 3.4.23
has caused the Debian Bug report #855320,
regarding developers-reference: Please do not recommend debrsign
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
855320: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=855320
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Package: developers-reference
Version: 3.4.18
Severity: normal
Control: tags -1 patch
Control: affects -1 devscripts

Please do not mention debrsign in the developers-reference.  The
workflow encouraged by debrsign is less secure than the one we'd like
to recommend for developers (it involves the untrusted machine having
ssh access to the trusted machine), so we should be trying to phase it
out.

Please also see discussion at https://bugs.debian.org/855282

Regards,

        --dkg


-- System Information:
Debian Release: 9.0
  APT prefers testing-debug
  APT policy: (500, 'testing-debug'), (500, 'testing'), (200, 'unstable-debug'), (200, 'unstable'), (1, 'experimental-debug'), (1, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.9.0-1-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

developers-reference depends on no packages.

Versions of packages developers-reference recommends:
ii  debian-policy  3.9.8.0

Versions of packages developers-reference suggests:
ii  doc-base  0.10.7

-- no debconf information

--- End Message ---
--- Begin Message ---
Source: developers-reference
Source-Version: 3.4.23

We believe that the bug you reported is fixed in the latest version of
developers-reference, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 855320@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Holger Levsen <holger@debian.org> (supplier of updated developers-reference package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 17 Feb 2019 13:44:03 +0100
Source: developers-reference
Architecture: source
Version: 3.4.23
Distribution: unstable
Urgency: medium
Maintainer: Developers Reference Maintainers <debian-policy@lists.debian.org>
Changed-By: Holger Levsen <holger@debian.org>
Closes: 376590 430889 483232 494470 775740 817914 839885 855320 908155
Changes:
 developers-reference (3.4.23) unstable; urgency=medium
 .
   [ Holger Wansing ]
   * Globally change "new maintainer" into "new member". Closes: #817914.
 .
   [ Holger Levsen ]
   * scope.dbk: extend: s#Debian developers#Debian developers and maintainers#
   * tools.dbk:
     - stop recommending remote signing of packages, especially using debrsign.
       Closes: #855320. Thanks to Daniel Kahn Gillmor.
     - slightly reword existing paragraph about dch and debchange.
       Closes: #494470.
   * best-pkging-practices.dbk: add another example of a multi binary source
     package. Closes: #430889.
   * l10n.dbk: drop paragraph about Debian specific manpages maintained in cvs.
   * developer-duties.dbk: improve paragraph about coordinating with upstreams.
     Closes: #908155. Thanks to Ian Jackson and Wouter Verhelst for the
     wording.
   * pkgs.dbk:
     - clarify the recipients of 123-submitter@b.d.o. Closes: #775740.
       Thanks to Josch Schauer for the wording.
     - don't suggest to test downgrading packages. Closes: #376590.
       Thanks to Justin Pryzby.
     - add a paragraph to the section about reintroducing packages to check and
       update the security tracker metadata. Closes: #839885.
       Thanks to Paul Wise.
   * beyond-pkging.dbk: mention mass-bugs for reporting bugs against many
     packages. Closes: #483232. Thanks to Sandro Tosi for the suggestion.
   * common.ent:
     - drop url-cvsweb.
     - switch five http urls to https, leaving one http url.
   * d/control: mark all binary packages as multiarch: foreign.
   * Update po4a/po/developers-reference.pot and po4a/po/*.po for the new and
     changed strings.
   * README.contributing:
     - renamed from README-contrib.
     - update instructions how to update .po files.
   * d/TODO: remove some ancient entries and clarify that only the BTS should
     be used in the long term.
Checksums-Sha1:
 dba327e74fe2ec51e98c6bf7a72c4c8ed742a78a 2398 developers-reference_3.4.23.dsc
 b83a10cf5cb15bd841e2d8bcb2787d286f85199c 671300 developers-reference_3.4.23.tar.xz
 4962327916996a353f4efcd7cad927c31c02fdd6 5187 developers-reference_3.4.23_source.buildinfo
Checksums-Sha256:
 b88ea3b436d735fdaaf022c9c26c099f374f2bcf9dd89db6a2813ddfd76ce90f 2398 developers-reference_3.4.23.dsc
 9abe6d60c2975bcf7cd25e930d6d0f1b0f6d150a41f41d09d3cd36115dde2477 671300 developers-reference_3.4.23.tar.xz
 013c4eccc6a890552db717cd51cd555de56705dbede2c78644f821b86db14bc1 5187 developers-reference_3.4.23_source.buildinfo
Files:
 8c01664a739cc087e8f72d5aa3d394ef 2398 doc optional developers-reference_3.4.23.dsc
 fb58bbc7005b1138a860805fdb8e76da 671300 doc optional developers-reference_3.4.23.tar.xz
 136e8bd2cdf29eeb8cae33094c999338 5187 doc optional developers-reference_3.4.23_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEuL9UE3sJ01zwJv6dCRq4VgaaqhwFAlxpW1UACgkQCRq4Vgaa
qhwoOw/8C5bb4KxQuciKRuTJIQ4ns4H76V8UFHJafR8iVym/iXIgm2xf9XRaHrz1
psRIZVroGJiyDjLy7ZaFaePgsod/aLAlGeerx2hEH1niWJDj0lItR+6UcCvDJuV+
mpWb/3565dbb78n5C/lhgg2E7D2AqGq4WcUHU8UxGH67+/oetG0yo0WJ/SMdcB6E
scHXk53byImiridkPiOnCtKlHb+UMy0/Llm7MZX9/tSTj+mASo3fjy/LGoaQpzFk
hdxKr+hAumAxbzTD8ohyi7dPq9fe5zNvMJ6eVgO46SNnYDwXGFTxC5yia/58m3Vm
ky1e2fY7vdPEdABTXlVp+2FJ0jacjIBljdkm2C+d0571ZgjADBZ128u3D6t2xw7g
hMzGNnOD7glqZyz/Nq1H4srMWNhTQf3q9D8cFdmIYfHW+7bmrGvqvL6PblghKCJg
ntX4t23utp/tOWI8SiaPyKjrH2ZuK/ibJ1/X836/I+b6Js4jVaU9haLyPS2J9kMy
FO8slTAtqir7CU5CDcDf7jJ8VuFpJ0lkys7NS0L5bH0eEkrvd0yP3GVq0zoM73Ib
k02QETc/TRzqIjlPeMpn9zIwWV7SgWDNLCxYO8lOksHaSWv4Yt0nEcd3eDhYp5G+
OFuU8acYQiMhwpht8pDTXSMFoqdTUNzaj90FqzbXHyuU/m3Df1Q=
=l6/N
-----END PGP SIGNATURE-----

--- End Message ---

Reply to: