Your message dated Mon, 23 Mar 2026 09:20:58 +0000
with message-id <[email protected]>
and subject line Bug#1093290: fixed in node-rollup 3.30.0-2
has caused the Debian Bug report #1093290,
regarding rollup emits Object.prototype.__proto__
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1093290: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1093290
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: rollup
Version: 3.29.5-1
Severity: normal

It seems that rollup emits `Object.prototype.__proto__`,
which is a problem because we decided to --disable-proto when
running pkgjs autopkgtests.

Example: node-prosemirror-view
https://ci.debian.net/packages/n/node-prosemirror-view/unstable/amd64/54772640/

Upstream rollup seems to be aware of it, but is ignoring the issue:
https://github.com/rollup/rollup/issues/3140

However their discussion was around __proto__, and did not make a distinction
between the two uses of it (one okay, one bad), so I tried to revive that issue.

Meanwhile, maybe we could either:
- patch rollup
- just use esbuild to build things...
- not use --disable-proto when the package build-depends on rollup

Jérémy
-- System Information:
Debian Release: trixie/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (500, 'testing')
Architecture: amd64 (x86_64)

Kernel: Linux 6.12.9-amd64 (SMP w/4 CPU threads; PREEMPT)
Locale: LANG=fr_FR.utf8, LC_CTYPE=fr_FR.utf8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages rollup depends on:
ii  nodejs  22.12.0+dfsg-3

rollup recommends no packages.

Versions of packages rollup suggests:
ii  node-chokidar  3.6.0-2

-- no debconf information

--- End Message ---
--- Begin Message ---
Source: node-rollup
Source-Version: 3.30.0-2
Done: Xavier Guimard <[email protected]>

We believe that the bug you reported is fixed in the latest version of
node-rollup, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Xavier Guimard <[email protected]> (supplier of updated node-rollup package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Mon, 23 Mar 2026 09:58:47 +0100
Source: node-rollup
Architecture: source
Version: 3.30.0-2
Distribution: experimental
Urgency: medium
Maintainer: Debian Javascript Maintainers 
<[email protected]>
Changed-By: Xavier Guimard <[email protected]>
Closes: 1093290
Changes:
 node-rollup (3.30.0-2) experimental; urgency=medium
 .
   * Team upload
   * Patch: avoid emitting __proto__ in generated output, use
     Object.setPrototypeOf instead (Closes: #1093290)
Checksums-Sha1: 
 3af315c4b1bdee2192c9cc196d531ca586e8c3e7 3370 node-rollup_3.30.0-2.dsc
 833beb76683f66d30822a65c4f89b091c0519d01 75432 
node-rollup_3.30.0-2.debian.tar.xz
Checksums-Sha256: 
 c90a9708b9b678b4c8df7e37a0c477e357642da6228e07cb6a00fe55f9225d02 3370 
node-rollup_3.30.0-2.dsc
 b36be694fcf0311f2cc4033def17c32283584792a9d727f9a7092d3216304f2d 75432 
node-rollup_3.30.0-2.debian.tar.xz
Files: 
 27389f4a494cefe2e7cc522dc7e0304a 3370 javascript optional 
node-rollup_3.30.0-2.dsc
 08d5fa3623168404e7c6bad98622f626 75432 javascript optional 
node-rollup_3.30.0-2.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmnBAT0ACgkQ9tdMp8mZ
7ul8iQ/8DJ+VmXl0lGYQ4/DPa2y0jV3zJ2GZGL+AhbSRcHypkbYzFPmMWgievJJo
SgBMdf1dOGZXFtY+Z7q65UUx0PyKy5TwisCR8Fok1kaCmjHayuKZY4PmB//GFW7S
eWcS+MaWFsz+Z4SxkZ3E5vjo6jpaSKxkKa18CC8ZeFYPxDHN4pjT7NfYiJFNSLQY
sFpcQLJ11idS4uh9eirgADP2sH9ikoXR2mhFo++7RUq+7D2tF/+WOnwv4qysatNi
7AVk0D/gUTBQRDkX4/xLcu63mO7DKfkCXcFRJLBi5XgyUGE6fxyAOLX0oladbyJW
N/x15qkBMYjKOJs7g2shuG2nignjXv0ZFiOasbXVIIgBYiOVbFOOaWMEAMD+JCNK
GG77XHvvFmIWjxYMUzeYUtugEmm8x6OhHktqDI0fVR5blttAeNyrAlSYlBBJgn1m
sJSOfHXvX1pGXz4x63O+L++rhoBPqpmsrlKxZ1syaBz/oV15BppGXC97VdQhuS2B
FkoXdoCU1xDL7T+Kn+bHGMmTcCGazGxM8ZGQjgVu1CtrRSPFVDtu616yS2Pl3OKt
P3H5DYvWFJvaggtHwFPjRpW5mqqy9kJxCGnJ9wjECGTOw8iVieftpxvcJgxL7LWQ
WioG/ef3gbI9Lq5RdqctE7FUrL7vzJutQ4bXaLMmnAdUCKmfswA=
=VEmF
-----END PGP SIGNATURE-----

Attachment: pgphc1S2eW0AW.pgp
Description: PGP signature


--- End Message ---

Reply via email to