Package: ftp.debian.org
Severity: normal
X-Debbugs-Cc: [email protected]
Control: affects -1 + src:almanah
User: [email protected]
Usertags: remove

Dear FTP masters,

I request the removal of the almanah package from the Debian archive for the
following reasons:

1. Unmaintained dependency: almanah depends on libcryptui, whose upstream
   repository has been archived and is in read-only mode
   (https://gitlab.gnome.org/Archive/libcryptui). libcryptui no longer
   receives updates or security patches.

2. No upstream maintenance: almanah also lacks active upstream maintenance,
   making it impossible to migrate to a safer alternative to replace the
   libcryptui dependency.

3. Security implications: Keeping packages that depend on unmaintained
   cryptographic libraries poses a security risk to Debian users.

4. No reverse dependencies: The package has no reverse dependencies,
   so its removal will not affect other packages.

5. Related bug: Bug #1112383 already documents this issue and mentions
   plans to remove libcryptui from forky.

As the Debian package maintainer, I believe removal is the most appropriate
action to maintain archive security.

Thank you for your attention.

Reply via email to