-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 13 Feb 2017 16:25:02 +0100 Source: diffoscope Binary: diffoscope Architecture: source Version: 77 Distribution: unstable Urgency: medium Maintainer: Reproducible builds folks <reproducible-bui...@lists.alioth.debian.org> Changed-By: Mattia Rizzolo <mat...@debian.org> Description: diffoscope - in-depth comparison of files, archives, and directories Closes: 854723 854745 854783 Changes: diffoscope (77) unstable; urgency=medium . [ Chris Lamb ] * tests/comparators/utils: + Correct logic of module_exists, ensuring we correctly skip in case of modules containing a dot in their name. Closes: #854745 * comparators/utils/libarchive: + No need to track archive directory locations. * Add --exclude option. Closes: #854783 * Add PyPI badge to README.rst. * Update .travis.yml from http://travis.debian.net. . [ Mattia Rizzolo ] * Add CVE reference to the changelog of v76. * Add my key to debian/upstream/signing-key.asc. . [ Ximin Luo ] * comparators/utils/libarchive: + When extracting archives, try to keep directory sizes small. . diffoscope (76) unstable; urgency=medium . [ Chris Lamb ] * Extract archive members using an auto-incrementing integer, avoiding the need to sanitise filenames and avoiding writes to arbitrary locations. (Closes: #854723 - CVE-2017-0359) . [ Ximin Luo ] * Simplify call to subprocess.Popen Checksums-Sha1: 88ab09a8ecf57244ee21bd5c2f19a39b0f1c5062 2972 diffoscope_77.dsc b0c72453546afd30364c36aa2a86355d712ad55f 349436 diffoscope_77.tar.xz 619ab27596d84ee53ebe2e8924c3ad662e1deea8 16138 diffoscope_77_amd64.buildinfo Checksums-Sha256: 964f94d42f970ba32d73770e9d0c151fe149633cfb9054333bafe7df3f0271ee 2972 diffoscope_77.dsc c9adeb0bfb0c92a3501df04b6ea4300c3896f15a9008803e4e12c1f312528499 349436 diffoscope_77.tar.xz 3e10be4a12c432443536830551d536e73dbb4de8f1374cf7ec6c5a033104a793 16138 diffoscope_77_amd64.buildinfo Files: 853b57d21d18fafb72701114b189a315 2972 devel optional diffoscope_77.dsc 13f5d4623bfd49a3787a3d03c9f4f076 349436 devel optional diffoscope_77.tar.xz dc24dbcee5c0028bc590f98a97504d14 16138 devel optional diffoscope_77_amd64.buildinfo
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEi3hoeGwz5cZMTQpICBa54Yx2K60FAlih0y4ACgkQCBa54Yx2 K61wdBAAlmhCj1QjMML0C7SgOprVNYmKhIwo+MzW0DHD4Mn3FaTU6v2QdtCO3Sev /kFVQDf2Tv+qAZhJ4h67a0hF710myt5faZVkMCqtCUsiVaNs/Q3py5wZAkJgpXMO C6gEP1rCQctDGKricbLasYhv71iUU6MNQym4G1sohJxi74fQ+CM1+STvCV3MIfIm SivzqSLja/lnyuRdHFjSIhPwR0tSoePmwQaNR7omd4EhC8seFS7vVcnRqO9bwSWz khZpLPKvSEdLfzLDjNGo4trFi6EEyMkdOh+Oqy2RQNYmVr1YQYkmNTn284FUQduv YxTG2/iFbdCWnYp+94RZI22TTJwBUsiAssAGFJD3e89ID6aPrjX/nq0ojHvz8mLF NWt/KySh2tkFzMCRP3d61hVm0QASPp1oXWHhxSBkXt1DPOQ6ujtsbme62bLZAh0r xco5c+JbRPMcjlNd4dZMy9qG0kjs+pRP6gF6qMbh8DXyPRAJrDQ8Y13U0dNKYzR+ ND9+dsVuFn/crrvjJqkowr4PqiQNbAa1zGQJtsxVXpw5Y8HtRPHNSWR976orR2Cp QmqzEXCy9L+jN9oU9l/dKtRSBqvDckUZVfO6g177uasPAMdC3h3V/2WsFqXylDP6 AQxDrS/qia2YczKWytJ0LgluQsvmQn5j+93IhpyJNCJPaTwa5U0= =QV/2 -----END PGP SIGNATURE-----