[ubuntu/focal-security] cargo 0.67.1+ds0ubuntu0.libgit2-0ubuntu0.20.04.2 (Accepted)

Nishit Majithia nishit.majithia at canonical.com
Wed Jul 5 09:36:30 UTC 2023


cargo (0.67.1+ds0ubuntu0.libgit2-0ubuntu0.20.04.2) focal; urgency=medium

  * Backport to Focal (LP: #2005123)
    - d/control: Remove dh-cargo from B-D
  * Re-enable libgit2 vendoring:
    - d/control: Remove libgit2-dev and libhttp-parser-dev from B-D

cargo (0.67.1+ds0ubuntu1-0ubuntu1) lunar; urgency=medium

  * Update to Cargo 0.67.1 (LP: #2005123)
    - d/vendor-tarball-unsuspicious.txt: update unsuspicious list to exclude
      removed source files
    - d/p/cve/*: remove patches that are merged upstream
    - d/make_orig_multi-pre-vendor.sh: downgrade clap to 4.0.15 to avoid
      some UI tests behaving incorrectly
    - d/p: refresh debian patches to adapt to Cargo 0.67.1
    - d/debcargo-conf.patch: refresh debconf patches to adapt to newer
      vendored dependencies
    - d/copyright: update copyright information for vendored dependencies

cargo (0.66.0+ds1-1ubuntu1) lunar; urgency=medium

  * Merge from Debian unstable (LP: #2000839):
    Remaining changes:
    - Add an explicit mechanism to customize the vendoring process
    - d/p/proxy-skip-tests.patch: skip a test when there's a proxy configured
      to accommodate Ubuntu autopkgtest setup
    - d/p/i386-crossbuild-tests.patch: disable some failing tests for
      cross-building from i386
    - d/p/remove-badges.patch: remove badges from documentation for privacy
      reasons (refreshed)
    - autopkgtests: test on all arches on Ubuntu
    - d/control: update the Vcs fields to point to Launchpad
    - make_orig_multi.sh: fix orig tarball compression to xz on Ubuntu
    - Track vendored dependencies
    - Bump the libgit2-related crates to get libgit2 1.5.0 bindings
    - make_orig_multi.sh: only use xz for vendor orig tarball on Ubuntu
  * Update vendored sources information

cargo (0.66.0+ds1-1) unstable; urgency=medium

  [ Fabian Gr├╝nbichler ]
  * fix CVE-2022-46176 (Thanks Peter Green!)
  * repack vendored sources with required libgit2-sys/git2/git2-curl versions
  * update unsuspicious files

Date: 2023-03-08 22:36:14.320219+00:00
Changed-By: Zixing Liu <zixing.liu at canonical.com>
Signed-By: Nishit Majithia <nishit.majithia at canonical.com>
https://launchpad.net/ubuntu/+source/cargo/0.67.1+ds0ubuntu0.libgit2-0ubuntu0.20.04.2
-------------- next part --------------
Sorry, changesfile not available.


More information about the Focal-changes mailing list