summaryrefslogtreecommitdiff
path: root/security/caff
AgeCommit message (Collapse)AuthorFilesLines
2022-06-28*: recursive bump for perl 5.36wiz1-2/+2
2021-10-26security: Replace RMD160 checksums with BLAKE2s checksumsnia1-2/+2
All checksums have been double-checked against existing RMD160 and SHA512 hashes Unfetchable distfiles (fetched conditionally?): ./security/cyrus-sasl/distinfo cyrus-sasl-dedad73e5e7a75d01a5f3d5a6702ab8ccd2ff40d.patch.v2
2021-10-07security: Remove SHA1 hashes for distfilesnia1-2/+1
2021-05-24*: recursive bump for perl 5.34wiz1-2/+2
2020-08-31*: bump PKGREVISION for perl-5.32.wiz1-1/+2
2020-07-17caff: update to 2.11.wiz3-14/+13
Only packaging changes.
2019-08-11Bump PKGREVISIONs for perl 5.30.0wiz1-1/+2
2019-05-21caff: update to 2.10.wiz2-7/+7
signing-party (2.10-1) unstable; urgency=high * gpg-key2ps: Security fix for CVE-2018-15599: unsafe shell call enabling shell injection via a User ID. Use Perl's (core) module Encode.pm instead of shelling out to `iconv`. (Closes: #928256.)
2019-03-20caff: update to 2.9.wiz2-7/+7
No relevant changes.
2019-02-14caff: Fix build under macOS and possibly other platformstron1-2/+2
Add GNU sed to the list of required build tools because the makefile uses the non standard option "-i".
2019-02-13caff: update to 2.8.wiz3-16/+14
signing-party (2.8-1) unstable; urgency=low [ Guilhem Moulin ] * caff: + Add the "only-sign-text-ids" to the list of gpg(1) options imported from ~/.gnupg/gpg.conf. + Ensure the terminal is "sane enough" when asking questions ('echo', 'echok', 'icanon', 'icrnl' settings are all set), and restore original settings when exit()'ing the program. (Closes: #872529) * caff, gpglist, gpgsigs: in `gpg --with-colons` output, allow signature class to be followed with an optional revocation reason. gpg(1) does that since 2.2.9. (Closes: #905097.) * caff, gpg-key2latex, gpg-key2ps, gpglist, gpgsigs, keylookup: Remove references to https://pgp-tools.alioth.debian.org/ . * caff, gpg-key2latex, gpg-key2ps, gpg-mailkeys, gpglist, gpgparticipants, gpgsigs, keylookup: Remove SVN keywords ($Id$, $Rev$, etc.) -- Guilhem Moulin <guilhem@debian.org> Mon, 28 Jan 2019 03:05:33 +0100
2018-08-22Recursive bump for perl5-5.28.0wiz1-1/+2
2018-02-11caff: update to 2.7.wiz2-7/+7
Bugfix release.
2017-09-02Fix bad merge on patch file which broke the build under macOS Sierra.tron2-8/+10
2017-08-29Fix gnupg2 dependency pattern.wiz1-2/+2
2017-08-29Remove references to gnupg21 in preparation for its removal.wiz1-5/+3
2017-08-14Updated caff to 2.6.wiz3-16/+15
Bugfixes.
2017-06-06Allow choosing gnupg1, gnupg2, or gnupg21. Default to gnupg2. Bump PKGREVISION.wiz2-2/+20
2016-10-09Updated caff to 2.5.wiz2-7/+7
Mostly documentation fixes.
2016-08-24Updated caff to 2.4.wiz2-8/+7
signing-party (2.4-1) unstable; urgency=medium * caff, gpg-key2latex, gpgsigs: Ignore "KEY_CONSIDERED" status output emitted by gpg 2.1.13 and later. * caff, gpgsigs: Allow input produced by gpgparticipants(1) using gpg 2.1.13. With this version, key IDs are not displayed by default and the "Key fingerprint = " prefix is omitted. * caff: + Fix GnuPG version number comparison. + With GnuPG 2.1.13 or later, use gpgconf(1) to determine the socket paths. (It is not used on earlier gpg since earlier gpgconf do not support --homedir.) This fixes compatibility with GnuPG 2.1.13. (Closes: #834984) + When ~/.caff/gnupghome/gpg.conf does not exist, instead of creating a temporary file (as it's done since signing-party 2.3), parse ~/.gnup/gpg.conf and pass the GnuPG options that are known to be safe (and useful) for caff to gpg(1) using command line options. This soves the problem of lingering configuration files in case caff is killed. + Use full fingerprints internally to avoid collisions. (However $CONFIG{'keyid'} and $CONFIG{'local-users'} are kept to 64-bits key IDs as per RFC 4880 full fingerprints are not available in key signatures, and thus not exposed by `gpg --with-colons --list-sigs`.) + Automatically import the $CONFIG{'also-encrypt-to'} from the normal GnuPGHOME when possible. * d/source.lintian-overrides: Add 'debian-watch-file-is-missing' as we're upstream. * d/control: Remove Franck Joncourt from the Uploaders list per request of the MIA team. (Closes: #831321) -- Guilhem Moulin <guilhem@guilhem.org> Mon, 22 Aug 2016 00:19:48 +0200
2016-07-09Bump PKGREVISION for perl-5.24.0 for everything mentioning perl.wiz1-1/+2
2016-05-05Don't attempt to build "keyanalyze" and friends. We don't install thosetron3-6/+17
programs anyway and it breaks the build under at least Mac OS X. After this change we also don't need various "auto*" tools during the build phase.
2016-05-05Updated caff to 2.3.wiz3-27/+7
No changelog found, but changes look like caff will take over more from the users default config.
2015-12-27Update caff to 2.2.wiz2-7/+7
Pattern fixes for signature recognition.
2015-11-04Add SHA512 digests for distfiles for security categoryagc1-1/+2
Problems found locating distfiles: Package f-prot-antivirus6-fs-bin: missing distfile fp-NetBSD.x86.32-fs-6.2.3.tar.gz Package f-prot-antivirus6-ws-bin: missing distfile fp-NetBSD.x86.32-ws-6.2.3.tar.gz Package libidea: missing distfile libidea-0.8.2b.tar.gz Package openssh: missing distfile openssh-7.1p1-hpn-20150822.diff.bz2 Package uvscan: missing distfile vlp4510e.tar.Z Otherwise, existing SHA1 digests verified and found to be the same on the machine holding the existing distfiles (morden). All existing SHA1 digests retained for now as an audit trail.
2015-08-14Update to 2.1:wiz2-7/+6
make gnupg executable configurable find out its version
2015-06-12Recursive PKGREVISION bump for all packages mentioning 'perl',wiz1-1/+2
having a PKGNAME of p5-*, or depending such a package, for perl-5.22.0.
2015-04-19Update to 2.0:wiz2-6/+6
Allow configuring the GPG executable, improve documentation.
2015-01-10Simplify PKGNAME.wiz1-3/+4
2015-01-04Update to 1.1.12:wiz2-6/+6
Allow option to set subject.
2014-11-19Update to 1.1.11: locale improvements.wiz2-6/+6
2014-10-12Update to 1.1.10: locale improvements.wiz2-6/+6
2014-08-31Update to 1.1.9:wiz2-6/+6
Diff looks like perl style cleanups.
2014-07-22Update to 1.1.8.wiz2-7/+6
New keyart binary (not installed) documenation improvements.
2014-07-16Caff was packaged fine, but a module was missing at run.mef1-2/+3
Add dependency +DEPENDS+= p5-Net-IDN-Encode-[0-9]*:../../textproc/p5-Net-IDN-Encode and bump PKGREVION. Thanks gdt@ for review.
2014-05-29Bump for perl-5.20.0.wiz1-1/+2
Do it for all packages that * mention perl, or * have a directory name starting with p5-*, or * depend on a package starting with p5- like last time, for 5.18, where this didn't lead to complaints. Let me know if you have any this time.
2014-05-20Update to 1.1.7, changes not found.wiz2-7/+8
2014-04-18Update to 1.1.6, changes not found.wiz3-8/+30
2014-02-03Update to 1.1.5: bugfixes, e.g. for perl-5.18 compat.wiz2-7/+6
2013-05-31Bump all packages for perl-5.18, thatwiz1-2/+2
a) refer 'perl' in their Makefile, or b) have a directory name of p5-*, or c) have any dependency on any p5-* package Like last time, where this caused no complaints.
2013-04-13Hand in maintainership.ghen1-2/+2
2012-10-23Drop superfluous PKG_DESTDIR_SUPPORT, "user-destdir" is default these days.asau1-3/+1
2012-10-03Bump all packages that use perl, or depend on a p5-* package, orwiz1-1/+2
are called p5-*. I hope that's all of them.
2011-11-28Update to 1.1.4:wiz2-6/+6
signing-party (1.1.4-1) unstable; urgency=low . [ Thijs Kinkhorst ] * caff: + Correct path of ~/.caffrc in informational messages (Closes: #582603). + Be more verbose on unexpected key ID (Closes: #645792). * gpg-key2ps: + Apply patch from Uwe Kleine-König to deal with latin1 characters (Closes: #596377). . [ Franck Joncourt ] * gpg-mailkeys: + Correct path of ~/.gpg-mailkeysrc and ~/.signature in manpage. + Add new environment variable SENDMAIL_ARGS to allow user to pass arguments to sendmail (closes: #599409). * caff: + Refactor import of own key and import for keys to sign from keyrings. + Also automatically import keys to sign from the user's normal gpg keyrings. + Use --no-auto-check-trustdb when importing keys from files or the user's normal gpg keyrings (closes: #539643). . [ Peter Palfrader ] * caff: + manpage: Refer to all of /usr/share/doc/signing-party/caff/ and not just to /usr/share/doc/signing-party/caff/caffrc.sample (closes: #568052). + Fix horrible &function calls used because of broken prototypes. + Even if all keys to sign were found in the user's normal gpg keyrings we still need to import them (again) from any keyrings passed with --key-files - the keys there might be newer, containing new subkeys (for encryption), uids (for signing) or revocations. + Make importing of keys to be signed from the normal gpg optional (--keys-from-gnupg). + refactor copying of command line options into global config variable. + Create the mail files in ~/.caff/keys even if mail is not sent (closes: #590666).
2010-02-16Update to 1.1.3:wiz2-6/+6
* keylookup: + Fixed typo noticed by lintian in manpage keylookup.1. * caff: + Set the Sender header with the email address which is used for the From header. This overrides the default value which was set by the MIME::Entity Perl module based on the local hostname. (Closes: #556782)
2009-10-31Update to 1.1.2:wiz2-6/+6
* gpgsigs: + Added patch from Roland Rosenfeld to support RIPEMD160 checksum. (Closes: #533747). + Updated man page to mention support for SHA256 and RIPEMD160 checksum. + Made removal of nonexistent photos quiet by the use of the force option. + Updated generated tex file in latex mode so that it uses the grffile package. This allows pdflatex to process our tex file assuming the photos are previously converted to PDF. (Closes: #542478) * caff: Updated check for the local-user keyids. + Moved the current check to a new function get_local_user_keys(). + Warned the user if a local-user keyid is not listed as a keyid in ./caffrc. (Closes: #540165). * gpgdir: New upstream release. * gpg-mailkeys: + The charset for the text of the message is deduced from the charset used by ~/.gpg-mailkeysrc and ~/.signature. The text message is encoded in quoted printable and thus it requires a new dependency on qprint in debian/control. (Closes: #545186) + Mentionned both the .gpg-mailkeysrc and .signature files in the manpage.
2009-07-10Correct license syntax.tron1-2/+2
2009-07-10Set the license to modified-bsd (caff) and gnu-gpl-v2 (the other tools).tron1-2/+2
2009-07-10Update the "caff" package to version 1.1.1. The changes are undocumented.tron2-7/+8
2009-06-14Remove @dirrm entries from PLISTsjoerg1-3/+1