apache-arrow (25.0.0-2) unstable; urgency=medium . * add gandiva-riscv64-pic-jit.patch: build the riscv64 Gandiva JIT PIC, fixing test_gandiva R_RISCV_HI20 out-of-range failures apache-arrow (25.0.0-1) unstable; urgency=medium . [ Rene Engelhard ] * drop r-4.6.diff, applied upstream . [ Dominique Belhachemi ] * New upstream version 25.0.0 * switch to soname 2500 * refresh use-debian-mimalloc.patch, restore DEP-3 header * debian/control: add pybuild-plugin-pyproject and python3-scikit-build-core to Build-Depends * switch pybuild from the distutils plugin to the pyproject plugin * pyarrow now builds with scikit-build-core instead of setup.py * debian/python3-pyarrow.install: .egg-info -> .dist-info * debian/copyright: drop ci/conan stanzas, removed upstream * Standards-Version: 4.7.4 (no changes needed) * debian/control: drop redundant Priority field from the source stanza * add new patch build-sse4.2-kernels.patch, keeps SIMD dispatch with the x86-64-v1 baseline * fixes autopkgtest failures with pandas 3.0 (Closes: #1142515) * debian/tests/control: add python3-pytz * drop the duplicate python bridge-lib copies apache-arrow (25.0.0-1~exp1) experimental; urgency=medium . [ Rene Engelhard ] * drop r-4.6.diff, applied upstream . [ Dominique Belhachemi ] * New upstream version 25.0.0 * switch to soname 2500 * refresh use-debian-mimalloc.patch, restore DEP-3 header * debian/control: add pybuild-plugin-pyproject and python3-scikit-build-core to Build-Depends * switch pybuild from the distutils plugin to the pyproject plugin * pyarrow now builds with scikit-build-core instead of setup.py * debian/python3-pyarrow.install: .egg-info -> .dist-info * debian/copyright: drop ci/conan stanzas, removed upstream * Standards-Version: 4.7.4 (no changes needed) * debian/control: drop redundant Priority field from the source stanza * add new patch build-sse4.2-kernels.patch, keeps SIMD dispatch with the x86-64-v1 baseline apt (3.3.2) unstable; urgency=medium . [ Julian Andres Klode ] * Document and test combined `build-dep --arch-only --indep-only` * ftparchive: fix heap overflow in ContentsExtract::DoItem * deb: guard against unsigned underflow when trimming control newlines * gpgv: don't advance past the null terminator in PushEntryWithKeyID * ftparchive: replace ContentsExtract's manual buffer with std::vector * test: Limit valgrind to 1024 open files * hashes: Fix lingering OpenSSL error (Closes: #1140227) * test: use `gnurm` where available * Convert command-line option-parsing to declarative format * Fix crash when an aux file request is redirected * Reply to aux requests with the original URI if redirected * debian/apt-daily.service: Add timeouts. 30 mins for apt-daily.service, 12 hours for apt-daily-upgrade.service should be sufficient. (LP: #2158000) . [ наб ] * apt-transport-https(1): document host-specific SSLCert, SSLKey, Verify-Host with host:: instead of ::host . [ David Kalnischkies ] * aptwebserver: Refuse client immediately on TLS handshake . [ Américo Monteiro ] * Portuguese manpages translation update (Closes: #1133965) . [ Frans Spiesschaert ] * Dutch program translation update (Closes: #1135221) * Dutch manpages translation update (Closes: #1135222) . [ Remus-Gabriel Chelu ] * Romanian program translation update (Closes: #1139336) . [ Mark Atwood ] * hashes: include for std::span * hashes: don't crash on an unavailable digest * test: exercise hashes with a disabled digest . [ dongshengyuan ] * Fix installing a deb with colon in path . [ Simon Johnsson ] * apt-pkg: rename "OpenPGP signature verification failed" to "Signature verification failed" . [ Andreas Noteng ] * Norwegian Bokmål (nb) translation update . [ Temuri Doghonadze ] * po: Add Georgian translation . [ Andriy Pysyk ] * Update Ukrainian translation for 3.3.1 . [ Mikhail Khachayants ] * srvrec: reject res_query answers bigger than our buffer . [ Ramesh Adhikari ] * tagfile: fix unbounded backward scan in Fill()'s trailing-newline check damo (3.3.5-1) unstable; urgency=medium . * New upstream version 3.3.5 emacs-bazel-mode (0.0.3-1) unstable; urgency=medium . * New upstream release * Update d/watch to track upstream tags * Drop compression settings in d/gbp.conf; prefer upstream git-merge-changelog (1:1.0-5) unstable; urgency=medium . * Team upload. * debian/control: Drop myself from the uploaders list. golang-github-sigstore-sigstore (1.10.9-1) unstable; urgency=medium . * Drop avoid-boulder (fixed upstream) * Use compat 14 golang-github-smallstep-pkcs7 (0.2.3-1) unstable; urgency=medium . * New upstream version 0.2.3 * Drop B-D/D golang-golang-x-crypto-dev * Improve d/copyright * Drop Depends: ${misc:Depends} * Drop d/.gitignore * Silence lrc for d/copyright * Update copyright years for recent contributors * Drop redundant `Priority: optional` * Drop redundant `Rules-Requires-Root: no` * Bump Debian Policy version to 4.7.4 * Use watch v5 * Use watch v5 * Use compat 14 * Drop --buildsystem=golang * Modernize Salsa CI golang-github-spiffe-go-spiffe (2.8.1-1) unstable; urgency=medium . * Use gbp sign-tags and upstream-vcs-tag golang-github-spiffe-go-spiffe (2.6.0-5) unstable; urgency=medium . * Upload to unstable * Update copyright years for recent contributors * Drop redundant `Priority: optional` * Bump Debian Policy version to 4.7.4 * Bump compat to 14 . golang-github-spiffe-go-spiffe (2.6.0-4) experimental; urgency=medium . * debian/control: matches XS-Go-Import-Path from go.mod file. golang-github-spiffe-go-spiffe (2.6.0-4) experimental; urgency=medium . * debian/control: matches XS-Go-Import-Path from go.mod file. groonga (16.0.8+dfsg-2) unstable; urgency=medium . * debian/patches/fix-ftbfs-with-apache-arrow-25.patch - Add patch to fix ftbfs with apache-arrow 25 (Closes: #1143520) hdf5 (2.1.0+repack-1) unstable; urgency=medium . * New major upstream release * Build with cmake (autotools support dropped upstream) * Flavors (serial, openmpi, mpich) are configured at build time using the cmake variable HDF5_LIB_INFIX * Other adjustments are done via the script debian/flavor-layout * Install cmake configuration files * New patch cmake.patch to adapt these files to our installation layout * New alternative hdf5.cmake to choose a given flavor as default cmake configuration * Helpers h5cc et al: set -norpath as the default * pkg-config files: - set the Requires variable to the related MPI backend - add the PluginDir variable * Build tools separately so that the cmake configuration files don't check for them * Java: - ship the JNI implementation to support a larger set of Java source versions (FFM implementation support starts at Java 25) - install maven artifacts * Patches from upstream: - fix the Java dependency tree - fix FTBFS during tests for s390x - fix the 'Extra libraries' field in libhdf5.settings * libhdf5-mpi-dev: - add symlinks for include and lib directories - set symlink hdf5_mpi.pc - drop support for 'hdf5-mpi.pc' as a slave of the 'mpi' alternatives - keep hdf5-mpi.pc symlink for backward compatibility (will be dropped at some point in the future) * Raise tests timeout to prevent FTBFS on riscv64 . * d/copyright: - added section for doxygen/doxygen-awesome.css - changed the main HDF5 license's short name from "BSD-5-clause" to "HDF5", and added a comment field * Updated symbols files * Lintian: - added comments to explain why the related warnings are overridden - removed overrides for the missing manpages to keep this task in mind - errors: these are caused by dwz bug #1106590 hdf5 (2.1.0+repack-1~exp11) experimental; urgency=medium . * Disable RPATH / RUNPATH by default in helpers hdf5 (2.1.0+repack-1~exp10) experimental; urgency=medium . * Fix wrong plugin path in pkgconfig files hdf5 (2.1.0+repack-1~exp9) experimental; urgency=medium . * Fix plugindir.patch in pkg-config files * Fix the 'Extra libraries' field in libhdf5.settings with: - upstream patch pr-6218.patch - complementary patch settings-extra-libraries.patch hdf5 (2.1.0+repack-1~exp8) experimental; urgency=medium . * pkg-config files: - set the Requires variable to the related MPI backend - add the PluginDir variable * libhdf5-mpi-dev: - add symlinks for include and lib directories - set symlink hdf5_mpi.pc - keep hdf5-mpi.pc symlink for backward compatibility (will be dropped at some point in the future) * Raise tests timeout to prevent FTBFS on riscv64 hdf5 (2.1.0+repack-1~exp7) experimental; urgency=medium . * Install cmake configuration files * New patch cmake.patch to adapt these files to our installation layout * New alternative hdf5.cmake to choose a given flavor as default cmake configuration * Build tools separately so that the cmake configuration files don't check for them * Fix typo in cmake option to enable zlib support hdf5 (2.1.0+repack-1~exp6) experimental; urgency=medium . * Patch helpers.patch to fix scripts h5cc et al * Install pkgconfig files * Drop support for 'hdf5-mpi.pc' as a slave of the 'mpi' alternatives * libhdf5-mpi-dev: add pkgconfig link 'hdf5-mpi.pc' hdf5 (2.1.0+repack-1~exp5) experimental; urgency=medium . * Fix java lib install * New patches from upstream: - fix the Java dependency tree - fix FTBFS during tests for s390x * Drop the previous workaround for the java dependency tree issue * d/flavor-layout: exits gracefully if already triggered hdf5 (2.1.0+repack-1~exp4) experimental; urgency=medium . * d/copyright: changed the main HDF5 license's short name from "BSD-5-clause" to "HDF5", and added a comment field * Force the Java library to be built first (when enabled) to solve an issue in the dependency tree hdf5 (2.1.0+repack-1~exp3) experimental; urgency=medium . * d/copyright: added section for doxygen/doxygen-awesome.css * lintian-overrides files: - added comments to explain why the related warnings are overridden - removed overrides for the missing manpages to keep this task in mind hdf5 (1.14.6+repack-3~exp1) experimental; urgency=medium . * Build using cmake instead of autotools which will soon be deprecated for HDF5 insighttoolkit5 (5.4.6-2) unstable; urgency=medium . * Team upload * Raising Standards version to 4.7.4 (no change) * Building with HDF5 2.1.0, thanks to Gilles Filippini (Closes: #1139623) libconfig-inifiles-perl (3.002000-1) unstable; urgency=medium . * Declare compliance with Policy 4.7.4 with no changes. * Switch back to debhelper-compat now that debhelper 14 is out. * Add Salsa CI definitions. * New upstream release: - drop the CVE-2026-11527 patch, it was taken from upstream libsecrecy (0.0.5+ds-5) unstable; urgency=medium . * Rebuild to fix Multiarch conflict on the changelog. * d/control: drop redundant Priority: optional. * d/control: drop redundant Rules-Requires-Root: no. * d/control: declare compliance to standards version 4.7.4. * d/control: bump to debhelper-compat 14. * d/watch: bump to Gitlab uscan-template v5. mpg123 (1.33.7-1) unstable; urgency=medium . * New upstream version 1.33.7 (Closes: #1143495) * debian/: Refactor alternatives handling netcdf-parallel (1:4.10.1-1) unstable; urgency=medium . * New upstream release. Closes: #1123961 Refresh patches Fixes: CVE-2025-14932, CVE-2025-14933, CVE-2025-14934, CVE-2025-14935, CVE-2025-14936 * Update d/copyright * Update symbols files * Fix include path in pkgconfig files. Closes: #1036168, #977545, #1003943 * d/rules: Ensure repeat builds works node-rollup-plugin-license (3.7.1+ds-4) unstable; urgency=medium . * MA: foreign * Add autopkgtest offlineimap3 (8.0.3+dfsg-2) unstable; urgency=medium . * Add dependency to fix autopkgtest. offlineimap3 (8.0.3+dfsg-1) unstable; urgency=medium . * New upstream version 8.0.3+dfsg - Fixes CVE-2020-37248. (Closes: #1139329) - Fixes encoding errors. (Closes: #1127107) offlineimap3 (8.0.2+dfsg-2~exp1) experimental; urgency=medium . * Experimental build from testing branch. offlineimap3 (8.0.2+dfsg-1) unstable; urgency=medium . * Update d/watch file to version 5 * New upstream version 8.0.2+dfsg - Add build depend on pybuild-plugin-pyproject. - Update build rules. * Update Standards-Version to 4.7.4 * fix depends of transitional package. offlineimap3 (0.0~git20240826.db34745+dfsg-2) unstable; urgency=medium . * Team upload. * debian/tests/user.py: Use chpasswd to hash passwords (closes: #1084729). offlineimap3 (0.0~git20240826.db34745+dfsg-1) unstable; urgency=medium . * New upstream version 0.0~git20240826.db34745+dfsg * Fix autopkgtest on chroot * Update Standards-Version to 4.7.0 offlineimap3 (0.0~git20231218.d29a4dc+dfsg-4) unstable; urgency=medium . * Team Upload * Remove build-dependency on python3-six offlineimap3 (0.0~git20231218.d29a4dc+dfsg-3) unstable; urgency=medium . * Do not enable keyring by default. offlineimap3 (0.0~git20231218.d29a4dc+dfsg-2) unstable; urgency=medium . * Fix autopkgtest. offlineimap3 (0.0~git20231218.d29a4dc+dfsg-1) unstable; urgency=medium . * New upstream version 0.0~git20231218.d29a4dc+dfsg - Fixes NameError with fcntl. (Closes: #1057921) * Add autopkgtest for preauthtunnel with ssh. offlineimap3 (0.0~git20231201.77e70ed+dfsg-1) unstable; urgency=medium . * New upstream version 0.0~git20231201.77e70ed+dfsg - Add dependency on python3-rfc6555 - Add dependency on python3-keyring * stop background process after autotest offlineimap3 (0.0~git20230519.c9f44ad+dfsg-1) unstable; urgency=medium . * New upstream version 0.0~git20230519.c9f44ad+dfsg - Remove patch from upstream. * Update Standards-Version to 4.6.2 * Update copyright. offlineimap3 (0.0~git20211018.e64c254+dfsg-2) unstable; urgency=medium . * Team upload * Patch: Python 3.11 compatible threadsafety check (Closes: #1027837) offlineimap3 (0.0~git20211018.e64c254+dfsg-1) unstable; urgency=medium . * New upstream version 0.0~git20211018.e64c254+dfsg - Fixes oauth errors with TypeError. (LP: #1947441) - Fixes cert_fingerprint with self-signed certificate. (Closes: #995403) * Add an autopkgtest to test with self signed certificates. offlineimap3 (0.0~git20210825.4ca9c75+dfsg-1) unstable; urgency=medium . [ Guido Günther ] * d/control: Suggest python3-gssapi (Closes: #989715) . [ Sudip Mukherjee ] * New upstream version 0.0~git20210825.4ca9c75+dfsg - Sync patches with new upstream version. - Add ca-certificates to dependency. - Fixes encoding error. (Closes: #986139) - Uses ca-certificates from default location. (Closes: #833191) * Update Standards-Version to 4.6.0.1 offlineimap3 (0.0~git20210225.1e7ef9e+dfsg-4) unstable; urgency=medium . * Fix flaky autopkgtest. (Closes: #987165) - Disable TLS connection. - Wait for dovecot to run. offlineimap3 (0.0~git20210225.1e7ef9e+dfsg-3) unstable; urgency=medium . * Fix autopkgtest. - Run dovecot only if it is not running. offlineimap3 (0.0~git20210225.1e7ef9e+dfsg-2) unstable; urgency=medium . * Upload to unstable. * Add autopkgtest. * Add salsa CI. offlineimap3 (0.0~git20210225.1e7ef9e+dfsg-1) experimental; urgency=medium . * New upstream version 0.0~git20210225.1e7ef9e+dfsg - Refresh Debian specific patch. - Upstream added Multiple encoding support. (Closes: #981685, #981485) offlineimap3 (0.0~git20210218.76c7a72+dfsg-1) unstable; urgency=medium . * New upstream version 0.0~git20210218.76c7a72+dfsg - Remove upstream applied patches. - Update fixes broken folderincludes. (Closes: #982970) - Update fixes remoteusereval config. (Closes: #983249) * Fix reading password from Curses Blinkenlights. (Closes: #981949) * Fix gmail fetch with synclabels enabled. offlineimap3 (0.0~git20210105.00d395b+dfsg-3) unstable; urgency=medium . [ Guido Günther ] * Fix GSSAPI authentication (Closes: #810119, #969298) . [ Debian Janitor ] * Set upstream metadata fields: Bug-Database, Bug-Submit. . [ Sudip Mukherjee ] * Revert use of default sslcacertfile. (Closes: #981338, #981677) * Read string from remotepassfile. (Closes: #982625, #981063, #981385) - Thanks to Vagrant Cascadian for the original patch. offlineimap3 (0.0~git20210105.00d395b+dfsg-2) unstable; urgency=medium . * Add 'offlineimap' transitional package. - Removes python2 dependency from offlineimap. (Closes: #937184, #967184) offlineimap3 (0.0~git20210105.00d395b+dfsg-1) unstable; urgency=medium . * New upstream version 0.0~git20210105.00d395b+dfsg. * Add dependency on python3-distro. (Closes: #979136) * Upload to unstable. offlineimap3 (0.0~git20201230.feeafa1+dfsg-1) experimental; urgency=medium . * New upstream version 0.0~git20201230.feeafa1 * Update Standards-Version to 4.5.1 offlineimap3 (0.0~git20201110.74744ce+dfsg-1) experimental; urgency=medium . * Add repack in d/watch file. * New upstream version 0.0~git20201110.74744ce. - Update fixes the byte object encode error. (Closes: #973408) * Make modules private. offlineimap3 (0.0~git20201025.c850e74+dfsg-1) experimental; urgency=medium . * Initial release (Closes: #972512) phpunit-cli-parser (5.0.1+ds-1) unstable; urgency=medium . [ Sebastian Bergmann ] * Do not report an option that is spelled out in full as ambiguous . [ David Prévot ] * Actually drop tools/ directory * Last release is not signed * Upgrade upstream signing key to new packet format * Update standards version to 4.7.4 * Mimic the installation path during tests phpunit-recursion-context (8.0.1+ds-1) unstable; urgency=medium . [ Sebastian Bergmann ] * Improve performance of Context::contains() . [ David Prévot ] * Last release is not signed * Upgrade upstream signing key to new packet format. * Update standards version to 4.7.4, no changes needed. * Set upstream metadata fields: Security-Contact. * Actually drop tools/ directory * Mimic the installation path during tests qtpim-opensource-src (5.0~git20201102.f9a8f0fc+dfsg1-9) unstable; urgency=medium . [ Lionel Duboeuf ] * Team upload * Rewrite 0039-QVersitOrganizer-For-Timezone-datetime-export-VTIMEZ.patch * Add 0040-Make-VTIMEZONE-parsing-more-robust.patch . [ Jeremy Bícha ] * Remove unnecessary Build-Depends: dbus (Closes: #1122709) * Update debian/copyright.in (Closes: #1128718) * Remove obsolete Rules-Requires-Root: no field r-cran-estimatr (1.0.6-2) unstable; urgency=medium . * Team upload. * Packaging update (routine-update) * Standards-Version: 4.7.3 (routine-update) * Reflow Uploaders field (cme) * Remove Priority field (cme) * Restrict to 64-bits architectures (routine-update) * Restrict to little-endian architectures (routine-update) r-cran-estimatr (1.0.6-1) unstable; urgency=medium . * Team upload. * New upstream version * Standards-Version: 4.7.2 (routine-update) r-cran-estimatr (1.0.4-2) unstable; urgency=medium . * Team upload. * d/tests/control: also skip on i386 and riscv64. Closes: #1064921 * Standards-Version: 4.7.1 (routine-update) Set upstream metadata fields: Repository. r-cran-estimatr (1.0.4-1) unstable; urgency=medium . * Team upload. * New upstream version * Standards-Version: 4.7.0 (routine-update) r-cran-estimatr (1.0.2-1) unstable; urgency=medium . * New upstream version r-cran-estimatr (1.0.0-3) unstable; urgency=medium . * Exclude Architecture: !armel !armhf !ppc64el !s390x from debci tests since there are some flaky tests * Standards-Version: 4.6.2 (routine-update) r-cran-estimatr (1.0.0-2) unstable; urgency=medium . * Packaging update r-cran-estimatr (1.0.0-1) unstable; urgency=medium . * Initial release (closes: #1017383) r-cran-poorman (0.2.8+dfsg-1) unstable; urgency=medium . * Team upload. * Packaging update (routine-update) * Use uscan v5 $template template. (routine-update) * New upstream version * Standards-Version: 4.7.4 (routine-update) * Restrict to R packages team core architectures (routine-update) * Drop 'Rules-Requires-Root: no' from d/control (routine-update) * Remove leading article from Description synopsis. ruby-process-metrics (0.13.0-1) unstable; urgency=medium . * Use GitHub tags in the watch file. * New upstream release. * Enable the test suite. * Install the examples. ruby-rack (3.2.6-3) unstable; urgency=medium . * Team upload. * Add minitest-must-raise-correctly.patch to cherry-pick upstream commit fixing test failure (Closes: #1143406). ruby-rspec-pending-for (0.1.25-1) unstable; urgency=medium . * Team upload. * New upstream release. * Enable the test suite; update build dependencies. ruby-socksify (1.8.1-1) unstable; urgency=medium . * Team upload. . [ Cédric Boutillier ] * [ci skip] Update team name . [ Debian Janitor ] * debian/copyright: use spaces rather than tabs to start continuation lines. * Set upstream metadata fields: Bug-Submit. * Bump debhelper from old 12 to 13. * Update standards version to 4.5.1, no changes needed. . [ Lucas Nussbaum ] * debian/gbp.conf: Add for DEP-14 * debian/gbp.conf: remove trailing empty lines * debian/.gitattributes: remove * debian/salsa-ci.yml: use team-specific include . [ Simon Quigley ] * Fix old-fsf-address-in-copyright-file * Upgrade the watch file to version 5. * New upstream release (Closes: #1143408). * Refresh the upstream metadata. * Drop {XS,XB}-Ruby-Versions from control. * Update Standards-Version to 4.7.4. * Bump debhelper-compat to 14, dropping ${misc:Depends}, ${shlibs:Depends}, and ${ruby:Depends} from runtime dependencies. * Use --gem-install layout in rules. * Drop testsuite. ruby-stamp (0.7.0-1) unstable; urgency=medium . * Team upload. * Fix old-fsf-address-in-copyright-file * Upgrade the watch file to version 5. * New upstream release. * Fix testsuite invocation, dropping cucumber. * Update Standards-Version to 4.7.4, no changes needed. * Bump debhelper-compat to 14, dropping ${misc:Depends}, ${shlibs:Depends}, and ${ruby:Depends} from runtime dependencies. * Mark as Multi-Arch: foreign. rust-bytesize (2.7.0-1) unstable; urgency=medium . * Team upload. * Package bytesize 2.7.0 from crates.io using debcargo 2.8.4 * Disable benches rust-ed25519-dalek-2 (2.2.0+dfsg-1) unstable; urgency=medium . * Package ed25519-dalek 2.2.0 from crates.io using debcargo 2.8.3 rust-egg (0.6.0+ds-5) unstable; urgency=medium . * update watch file: + use Custom-Version + stop set auto-mangling of upstream version (now done by default) * provide minor-versioned and featured virtual packages * reorganize patch naming * use debhelper compatibility level 14 (not 13) * tighten (build-, autopkgtest-)dependencies * extend patch 1002_newer_ordered-float to accept newer major version of crate ordered-float rust-symbolic-expressions (5.0.3+ds-3) unstable; urgency=medium . * provide major-versioned package * tighten autopkgtest-dependencies * use debhelper compatibility level 14 (not 13) * update watch file: + stop set auto-mangling of upstream version (now done by default) rust-sysconf (0.3.4-2) unstable; urgency=medium . * Team upload * Package sysconf 0.3.4 from crates.io using debcargo 2.8.4 * Mark nightly feature test as flaky rust-sysconf (0.3.4-1) unstable; urgency=medium . * Package sysconf 0.3.4 from crates.io using debcargo 2.8.3 * debian/patches: remove win32 specific dependencies & relax others * Closes: #1142420 rust-taskchampion (2.0.2+dfsg-1) unstable; urgency=medium . * Team upload. * Package taskchampion 2.0.2 from crates.io using debcargo 2.8.3 scite (5.6.5-1) unstable; urgency=medium . * New upstream version 5.6.5 * Refresh patches * Don't remove pycache in dh_auto_clean silo-llnl (4.12.1-1) unstable; urgency=medium . * New upstream release thunderbird (1:140.13.0esr-2) unstable; urgency=medium . * [137fa88] d/control: Add python3-typing-extensions to B-D thunderbird (1:140.13.0esr-1) unstable; urgency=medium . * [41e5476] New upstream version 140.13.0esr Fixed CVE issues in upstream version 140.13 (MFSA 2026-72): CVE-2026-14899: Off-by-one out of bounds read in MIME header parser for forwarding CVE-2026-15718: Invalid pointer in the JavaScript: WebAssembly component CVE-2026-15719: Site isolation issue in the DOM: Navigation component CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component CVE-2026-16354: Information disclosure in the Graphics: ImageLib component CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component CVE-2026-16357: Incorrect boundary conditions in the Graphics component CVE-2026-16371: Privilege escalation in the DOM: Navigation component CVE-2026-16374: Information disclosure in the Framework component in DevTools CVE-2026-16375: Site isolation issue in the Networking: HTTP component CVE-2026-16377: Mitigation bypass in the PDF Viewer component CVE-2026-16379: Privilege escalation in the DOM: Content Processes component CVE-2026-16358: Site isolation issue in the Graphics: WebRender component CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component CVE-2026-16383: Mitigation bypass in the DOM: Networking component CVE-2026-16387: Site isolation issue in the Networking component CVE-2026-16390: Mitigation bypass in the Enterprise Policies component CVE-2026-16391: Information disclosure in the Storage: IndexedDB component CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component CVE-2026-16396: Privilege escalation in WebExtensions CVE-2026-16405: Information disclosure in the Networking: WebSockets component CVE-2026-16412: Memory safety bugs fixed in Thunderbird ESR 140.13 and Thunderbird 153 CVE-2026-16360: Memory safety bugs fixed in Thunderbird ESR 140.13 and Thunderbird 153 CVE-2026-16361: Memory safety bugs fixed in Thunderbird ESR 140.13 * [fe5c7e7] Rebuild patch queue from patch-queue branch Added patches (picked from firefox-esr): fixes/Bug-1969769-Change-uses-of-ast.Str-with-ast.Constant.-r-f.patch fixes/Bug-1983713-Use-non-deprecated-ast-value.-r-firefox-build.patch fixes/Bug-1983736-Patch-jsonschema-to-work-with-Python-3.14-r-m.patch . Adjusted patches (removed wrong used metadata field 'Forwared'): fixes/Add-missing-.gitmodules-files-which-are-needed-to-build-t.patch fixes/Fix-conflicting-types-for-once_flag-and-call_once-with-gl.patch fixes/Fix-sandbox-to-build-with-glibc-2.43.patch fixes/Install-vaapitest-v4l2test-only-when-build.patch * [79acc18] d/control: Increase Standards-Version to 4.7.4 No further changes needed. * [d6c0a0f] d/rules: Move/rename third party Python modul temporarly