Your message dated Fri, 09 Jan 2026 11:41:59 +0000
with message-id <[email protected]>
and subject line Bug#1118194: Removed package(s) from unstable
has caused the Debian Bug report #1118194,
regarding RM: libdkim -- RoM; Potentially insecure, dead upstream
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1118194: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1118194
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libdkim
Version: 1:1.0.21-4
Severity: important
X-Debbugs-Cc: [email protected], Magnus Holmgren <[email protected]>, 
Package Salvaging Team <[email protected]>

Dear Magnus,
 
I suggest removing libdkim from Debian for the following reasons:

 * Dead upstream
 * security concern since it allows trivially factorable keys to produce
   apparently valid signatures (see bug #893461)
 * There are nearly no votes in popcon
   
https://qa.debian.org/popcon-graph.php?packages=libdkim1d&show_vote=on&want_legend=on&want_ticks=on&from_date=&to_date=&hlght_date=&date_fmt=%25Y-%25m&beenhere=1
 * Vcs fields point to inaccessible SVN
 * Last upload 9 years ago
 
This bug serves as a pre-removal warning. After one month, the bug will be
reassigned to ftp.debian.org to actually request removal of the package.
 
In case the package should be removed from unstable, you may reassign this
bug report:
 
    Control: severity -1 normal
    Control: retitle -1 RM: libdkim -- RoM; Potentially insecure, dead upstream
    Control: reassign -1 ftp.debian.org
    Control: affects -1 + src:libdkim
 
Alternatively, you may wait a month and have it reassigned.
 
In case you disagree with the above, please add a wontfix tag to this bug.
 
    Control: tags -1 + wontfix
 
This package was highlighted in the Bug of the Day[3] initiative, which
aims to introduce newcomers to manageable tasks and guide them through
the workflow to solve them. The focus of this initiative is on migrating
packages to Salsa, as it's a great way to help newcomers become familiar
with a consistent Git-based workflow.
 
Kind regards
   Andreas.

[1] https://salsa.debian.org/qa/tiny_qa_tools/-/wikis/Tiny-QA-tasks


-- System Information:
Debian Release: forky/sid
  APT prefers testing
  APT policy: (501, 'testing'), (50, 'buildd-unstable'), (50, 'unstable'), (5, 
'experimental'), (1, 'buildd-experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 6.12.38+deb13-amd64 (SMP w/4 CPU threads; PREEMPT)
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8), 
LANGUAGE=de_DE:de
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

--- End Message ---
--- Begin Message ---
We believe that the bug you reported is now fixed; the following
package(s) have been removed from unstable:

   libdkim | 1:1.0.21-4 | source
libdkim-dev | 1:1.0.21-4 | loong64
libdkim-dev | 1:1.0.21-4+b4 | amd64, armhf, ppc64el, s390x
libdkim-dev | 1:1.0.21-4+b5 | i386, riscv64
libdkim-dev | 1:1.0.21-4+b6 | arm64
 libdkim1d | 1:1.0.21-4 | loong64
 libdkim1d | 1:1.0.21-4+b4 | amd64, armhf, ppc64el, s390x
 libdkim1d | 1:1.0.21-4+b5 | i386, riscv64
 libdkim1d | 1:1.0.21-4+b6 | arm64
libdkim1d-dbg | 1:1.0.21-4 | loong64
libdkim1d-dbg | 1:1.0.21-4+b4 | amd64, armhf, ppc64el, s390x
libdkim1d-dbg | 1:1.0.21-4+b5 | i386, riscv64
libdkim1d-dbg | 1:1.0.21-4+b6 | arm64

------------------- Reason -------------------
RoM; Potentially insecure, dead upstream
----------------------------------------------

Note that the package(s) have simply been removed from the tag
database and may (or may not) still be in the pool; this is not a bug.
The package(s) will be physically removed automatically when no suite
references them (and in the case of source, when no binary references
it).  Please also remember that the changes have been done on the
master archive and will not propagate to any mirrors until the next
dinstall run at the earliest.

Packages are usually not removed from testing by hand. Testing tracks
unstable and will automatically remove packages which were removed
from unstable when removing them from testing causes no dependency
problems. The release team can force a removal from testing if it is
really needed, please contact them if this should be the case.

We try to close bugs which have been reported against this package
automatically. But please check all old bugs, if they were closed
correctly or should have been re-assigned to another package.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected].

The full log for this bug can be viewed at https://bugs.debian.org/1118194

This message was generated automatically; if you believe that there is
a problem with it please contact the archive administrators by mailing
[email protected].

Debian distribution maintenance software
pp.
Thorsten Alteholz (the ftpmaster behind the curtain)

--- End Message ---

Reply via email to