• Bug#1106217: unblock: request-tracker5/5.0.7+dfsg-4

    From Andrew Ruthven@21:1/5 to All on Wed May 21 14:10:01 2025
    XPost: linux.debian.devel.release

    This is a multi-part MIME message sent by reportbug.


    Package: release.debian.org
    Severity: normal
    X-Debbugs-Cc: request-tracker5@packages.debian.org
    Control: affects -1 + src:request-tracker5
    User: release.debian.org@packages.debian.org
    Usertags: unblock

    Please unblock package request-tracker5

    [ Reason ]
    In previous major upgrades we have customised the UPGRADE instructions provided by upstream to refer to the paths we used in Debian. I realised yesterday that this hadn't been done for the 4.4 or the 5.0 instructions. I have tailored the instructions for Debian now, and believe we should provide this to our users
    in trixie.

    While we also missed this for bookworm, it will be more important in trixie.
    We are dropping request-tracker4, so will be forcing our users to make the major upgrade to request-tracker5 in trixie.

    [ Impact ]
    The UPGRADE instructions will be more confusing as they may look for commands to run, or files to modify which aren't where the instructions tell them.

    [ Tests ]
    There are no code changes.

    [ Risks ]
    There are no code changes.

    [ Checklist ]
    [x] all changes are documented in the d/changelog
    [x] I reviewed all changes and I approve them
    [x] attach debdiff against the package in testing

    [ Other info ]
    I have made a couple of minor corrections to d/changelog and adjusted
    d/watch to ignore the upcoming RT 6 release.

    unblock request-tracker5/5.0.7+dfsg-4

    diff -Nru request-tracker5-5.0.7+dfsg/debian/changelog request-tracker5-5.0.7+dfsg/debian/changelog
    --- request-tracker5-5.0.7+dfsg/debian/changelog 2025-05-04 17:51:52.000000000 +1200
    +++ request-tracker5-5.0.7+dfsg/debian/changelog 2025-05-21 20:43:14.000000000 +1200
    @@ -1,9 +1,19 @@
    +request-tracker5 (5.0.7+dfsg-4) unstable; urgency=high
    +
    + * Update d/watch to only look for versions that match 5.x.y as version 6 will
    + be handled by request-tracker6.
    + * Debianize the UPGRADING-4.4 and UPGRADING-5.0 instructions to use paths
    + etc that are used on Debian.
    +
    + -- Andrew Ruthven <andrew@etc.gen.nz> Wed, 21 May 2025 20:43:14 +1200
    +
    request-tracker5 (5.0.7+dfsg-3) unstable; urgency=high

    * Update Standards-Version to 4.7.2 (no changes).
    * Refresh d/copyright.
    * Add Catalan translation, thank you Carles Pina i Estany!
    - * Apply upstream patches which fix several security vulnerabilities.
    + * Apply upstream patches which fix several security vulnerabilities
    + (Closes: #1104422).
    - [CVE-2025-30087] Vulnerable to Cross Site Scripting via injection of
    mal