Your message dated Fri, 25 Oct 2024 12:28:22 +0200
with message-id <87msiszdbt....@kaka.sjd.se>
and subject line closing since no longer relevant
has caused the Debian Bug report #1085874,
regarding ITP: golang-github-theupdateframework-go-tuf-v2 -- The Update 
Framework (TUF) v2 Go library
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
1085874: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1085874
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: wnpp
Severity: wishlist
Owner: Simon Josefsson <si...@josefsson.org>

* Package name    : golang-github-theupdateframework-go-tuf-v2
  Version         : 2.0.2-1
  Upstream Author : The Update Framework (TUF)
* URL             : https://github.com/theupdateframework/go-tuf
* License         : Apache-2.0
  Programming Lang: Go
  Description     : Go implementation of The Update Framework (TUF)

 The Update Framework (TUF) helps developers maintain the security of software
 update systems, providing protection even against attackers that compromise
 the repository or signing keys. TUF provides a flexible framework and
 specification that developers can adopt into any software update system.

I hope to maintain this package as part of Debian Go Packaging Team:

https://salsa.debian.org/go-team/packages/golang-github-theupdateframework-go-tuf-v2

The current Debian package golang-github-theupdateframework-go-tuf is
for the old v0.x API, quoting upstream:

 The legacy go-tuf (v0.7.0) (https://github.com/theupdateframework/go-
 tuf/tree/v0.7.0) codebase was difficult to maintain and prone to errors
 due to its initial design decisions. Now it is considered deprecated in
 favour of go-tuf v2 (originaly from rdimitrov/go-tuf-metadata
 (https://github.com/rdimitrov/go-tuf-metadata)) which started from the
 idea of providing a Go implementation of TUF that is heavily influenced
 by the design decisions made in python-tuf
 (https://github.com/theupdateframework/python-tuf).

Indeed, I tried rebuilding the reverse dependencies of this package with
v2.x and while most packages actually built, there are some that fails
due to TUF v0 vs v2:

https://salsa.debian.org/jas/golang-github-theupdateframework-go-tuf/-/pipelines/751423

Since the package has a different license and looks like a complete
rewrite to me, I think it makes sense to have two separate Debian
packages for it.

/Simon

Attachment: signature.asc
Description: PGP signature


--- End Message ---
--- Begin Message ---
See https://lists.debian.org/debian-go/2024/10/msg00038.html

/Simon

Attachment: signature.asc
Description: PGP signature


--- End Message ---

Reply via email to