[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#1000006: marked as done (parser: depends on obsolete pcre3 library)



Your message dated Tue, 12 Dec 2023 12:50:34 +0000
with message-id <E1rD2Da-004JkZ-4U@fasolo.debian.org>
and subject line Bug#1000006: fixed in parser 3.4.6-4
has caused the Debian Bug report #1000006,
regarding parser: depends on obsolete pcre3 library
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
1000006: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1000006
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Source: parser
Severity: important
User: matthew-pcredep@debian.org
Usertags: obsolete-pcre3

Dear maintainer,

Your package still depends on the old, obsolete PCRE3[0] libraries
(i.e. libpcre3-dev). This has been end of life for a while now, and
upstream do not intend to fix any further bugs in it. Accordingly, I
would like to remove the pcre3 libraries from Debian, preferably in
time for the release of Bookworm.

The newer PCRE2 library was first released in 2015, and has been in
Debian since stretch. Upstream's documentation for PCRE2 is available
here: https://pcre.org/current/doc/html/

Many large projects that use PCRE have made the switch now (e.g. git,
php); it does involve some work, but we are now at the stage where
PCRE3 should not be used, particularly if it might ever be exposed to
untrusted input.

This mass bug filing was discussed on debian-devel@ in
https://lists.debian.org/debian-devel/2021/11/msg00176.html

Regards,

Matthew [0] Historical reasons mean that old PCRE is packaged as
pcre3 in Debian 

--- End Message ---
--- Begin Message ---
Source: parser
Source-Version: 3.4.6-4
Done: Yavor Doganov <yavor@gnu.org>

We believe that the bug you reported is fixed in the latest version of
parser, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1000006@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Yavor Doganov <yavor@gnu.org> (supplier of updated parser package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 12 Dec 2023 10:26:45 +0200
Source: parser
Architecture: source
Version: 3.4.6-4
Distribution: unstable
Urgency: medium
Maintainer: Debian QA Group <packages@qa.debian.org>
Changed-By: Yavor Doganov <yavor@gnu.org>
Closes: 1000006
Changes:
 parser (3.4.6-4) unstable; urgency=medium
 .
   * QA upload.
   * debian/patches/pcre2.patch: New; port to PCRE2 (Closes: #1000006).
   * debian/control (Build-Depends): Replace libpcre3-dev with
     libpcre2-dev.  Remove apache2-dev version constraint, satisfiable even
     in jessie.
     (Rules-Requires-Root): Set to "no".
     (Standards-Version): Bump to 4.6.2; no changes needed.
   * rules: Drop --with autoreconf; it's the default.
   * debian/watch: Upgrade to version 4.
   * debian/source.lintian-overrides: Rename as...
   * debian/source/lintian-overrides: ...and add
     license-problem-convert-utf-code (false positive).  Rename
     debian-watch-may-check-gpg-signature to
     debian-watch-does-not-check-openpgp-signature.
   * debian/copyright: Update copyright years, add more holders.  Add
     University of Illinois license.  Fix superfluous and redundant
     patterns; remove tabs in license text.
Checksums-Sha1:
 9f880f50471d61b411394ae939ed523cd4ae6754 1987 parser_3.4.6-4.dsc
 ec9adb8fdf63edb18d735fa84414017615b43265 47272 parser_3.4.6-4.debian.tar.xz
 771480a7f0f05eededa8df93ad082ce650375b31 5838 parser_3.4.6-4_source.buildinfo
Checksums-Sha256:
 d994e3ab8ca90d007bdb6ed2c73b6363159b59cebe56ae00f2db64058471555f 1987 parser_3.4.6-4.dsc
 d2699ba4426589da11d858cd4b71ebcd37b520a5f575eacced9bd4f2fbcadb25 47272 parser_3.4.6-4.debian.tar.xz
 398cd17f6596ace3f76b238a047d6803b728394b90ade33b3bf24c638309be19 5838 parser_3.4.6-4_source.buildinfo
Files:
 109d2031e0ef03917f6d35ab82ccd4fa 1987 web optional parser_3.4.6-4.dsc
 f60fc3d556436dff2ac962d550d4087c 47272 web optional parser_3.4.6-4.debian.tar.xz
 70d1fc4d03892c409b363f2b6c219bf6 5838 web optional parser_3.4.6-4_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQHEBAEBCgAuFiEEQGIgyLhVKAI3jM5BH1x6i0VWQxQFAmV4TccQHGJhZ2VAZGVi
aWFuLm9yZwAKCRAfXHqLRVZDFIcuDACChzr3L6ZUwdLvUxhfL0ZvGCFYvxHJzhy6
go7k50e/xjSMAzHncE6oRiY24ttkyyNaTrCRHmVK7/8u5gQ4OZ340mfLuzVz/SgO
xg8Eayl7dMNfr4NQQiLcCPbSCng/W0NQSlMAk12HN88RpP1vwXl6wdHr92rjnC+V
yS8ciw+qI/jbUMkInZCZQdopWb+Tg1AnT1JN2RKoCDjzuS8Cuv2DiJRpI1g1CtZX
alh2kwt3eZ8taUgqoz3Ht0WufI/0Axny6SCmGwdQUWhkoXyWbURRK5YXpFLwHRW8
65gJTQyn4gAZ+463LO78oi5PAnVogs7aW6CrZZCP3b5FlW2Cmkga5OFpVQtLsE0l
PUHeU9C+I6GhzQF82WwQyWsNzAgMnqs9NaPxuZ+4eAHGP0scex2UZfOjk4ToEe3Z
Sadt4Em/kgNfx6aocZ9tBo+1Yc7Iw9Vyy3CD03wUdTeEMITcDIG1WbALjbg/+mll
qeuMy7NzWdjGw7hbvW+Gpp+eVCP96R0=
=3Rp0
-----END PGP SIGNATURE-----

--- End Message ---

Reply to: