Hi Maytham, hi all, Fourteen dependencies of syft (https://bugs.debian.org/1124819) are ready and need uploads through NEW. Each is at salsa.debian.org/go-team/packages/<name> on debian/sid, with upstream and pristine-tar branches and no tags. Each builds in a clean unstable chroot, lrc reports no differences, and lintian is clean bar the long filenames the naming convention forces.
golang-github-dgraph-io-badger-v4 https://bugs.debian.org/1148678 golang-github-vifraa-gopom https://bugs.debian.org/1148625 golang-github-elliotchance-phpserialize https://bugs.debian.org/1148626 golang-github-kastenhq-goversion https://bugs.debian.org/1148627 golang-github-zyedidia-generic https://bugs.debian.org/1148628 golang-github-rust-secure-code-go-rustaudit https://bugs.debian.org/1148629 golang-github-deitch-magic https://bugs.debian.org/1148630 golang-github-google-licensecheck https://bugs.debian.org/1148631 golang-github-facebookincubator-nvdtools https://bugs.debian.org/1148638 golang-github-nix-community-go-nix https://bugs.debian.org/1148637 golang-github-anchore-go-lzo https://bugs.debian.org/1148639 golang-github-smallnest-ringbuffer https://bugs.debian.org/1148640 Upload order matters for two of them: golang-github-anchore-go-lzo before golang-github-diskfs-go-diskfs https://bugs.debian.org/1148636 golang-github-smallnest-ringbuffer before golang-github-gpustack-gguf-parser-go https://bugs.debian.org/1148632 Taken the other way round their build-dependencies will not resolve. Two more already had repositories, so they are merge requests: chardet, on the snapshot syft needs, ready to merge: https://salsa.debian.org/go-team/packages/golang-github-saintfish-chardet/-/merge_requests/1 go-getter, removed from unstable in January over five CVEs and reintroduced at 1.8.9, which is past all of them. Draft: it still needs go-netrc to ship a go.mod and aws-sdk-go-base to exist. https://salsa.debian.org/go-team/packages/golang-github-hashicorp-go-getter/-/merge_requests/2 If you have spare cycles, could you review and sponsor some or all of them? Maytham, our dependency table is updated: https://salsa.debian.org/go-team/packages/syft/-/wikis/PackagingDependenciesStatus Cheers, Juan
