Your message dated Sat, 22 Dec 2018 23:21:04 +0000
with message-id <[email protected]>
and subject line Bug#800993: fixed in jackrabbit 2.18.0-1
has caused the Debian Bug report #800993,
regarding jackrabbit: depends on obsolete libcommons-httpclient-java library
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
800993: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=800993
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: jackrabbit
Severity: normal
User: [email protected]
Usertags: oldlibs libcommons-httpclient-java
Hi,
jackrabbit depends on libcommons-httpclient-java, which is obsolete and was
replaced by libhttpclient-java. It has reached EOL status in 2011! It is no
longer supported upstream [1] and was affected by multiple security issues in
the recent past. jackrabbit should be ported to the new libhttpclient-java
version, so that we can remove the old, unmaintained one. Please forward this
issue upstream, if you can't migrate the package yourself.
We would like to see libcommons-httpclient-java removed during the Stretch
release cycle but due to the large number of reverse-dependencies the outcome
depends more than ever on your help.
Please help us to accomplish this goal. We will bump this issue to important
when the list of rdeps is getting smaller and we think that the removal is
possible. We will eventually raise the severity to serious when the number
of rdeps is small.
If you have any questions don't hesitate to ask and contact us on
[email protected]
Regards,
Markus
[1] https://hc.apache.org/httpclient-3.x/
[2]
https://security-tracker.debian.org/tracker/source-package/commons-httpclient
--- End Message ---
--- Begin Message ---
Source: jackrabbit
Source-Version: 2.18.0-1
We believe that the bug you reported is fixed in the latest version of
jackrabbit, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Markus Koschany <[email protected]> (supplier of updated jackrabbit package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sat, 22 Dec 2018 22:51:06 +0100
Source: jackrabbit
Binary: libjackrabbit-java
Architecture: source
Version: 2.18.0-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Java Maintainers
<[email protected]>
Changed-By: Markus Koschany <[email protected]>
Description:
libjackrabbit-java - content repository implementation (JCR API)
Closes: 800993
Changes:
jackrabbit (2.18.0-1) unstable; urgency=medium
.
* Team upload.
* New upstream version 2.18.0.
* Drop libcommons-httpclient-java. No longer needed. (Closes: #800993)
* Rebase servlet-api.patch.
Checksums-Sha1:
6f257a1582a41abf988e469b8579036b2fea996b 2254 jackrabbit_2.18.0-1.dsc
d6c1440bd2598dbb68c70bc7dee9769c0775517a 3390412 jackrabbit_2.18.0.orig.tar.xz
47a7914bc2c47626b7361de5fd4a7c7801dfd081 7412 jackrabbit_2.18.0-1.debian.tar.xz
92df1f84eebd209650dee89ba34932d52e0b41ed 15006
jackrabbit_2.18.0-1_amd64.buildinfo
Checksums-Sha256:
d7e36803423765afde9b1925b641df364ce54076da0fcde5a33ec55e51472a6d 2254
jackrabbit_2.18.0-1.dsc
bf081ca701d96bfc8748c93fba5ea8c96e9eeb85a5d94688aca06aff4b44ac16 3390412
jackrabbit_2.18.0.orig.tar.xz
94bda909dd0ce3eb346178793469deca0f98dfbee0b881514506ce4a1745ba88 7412
jackrabbit_2.18.0-1.debian.tar.xz
32e8721ce6411592d65804f563156c20c1fa0abdd5426a9a45776e8a8ab51e8b 15006
jackrabbit_2.18.0-1_amd64.buildinfo
Files:
aefdf125432063a6fcec8ffcaf03fc4f 2254 java optional jackrabbit_2.18.0-1.dsc
22b61f624de16fb0e2dcad7675044a5f 3390412 java optional
jackrabbit_2.18.0.orig.tar.xz
57ffd68ba3a19c85abf0bc4b5618bd29 7412 java optional
jackrabbit_2.18.0-1.debian.tar.xz
64d74cd027a73060a2f7eda54d021efc 15006 java optional
jackrabbit_2.18.0-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAlwev/lfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD
RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp
YW4ub3JnAAoJENmtFLlRO1Hkjy0QAIpL8MgdCEvdd8NLfGxuJYvQVorOjxc+WQKA
8iLuoXwQsN6MafozzVImC7N285ZhsPF3Ql0KgSFpepyoS0gnyFu5PyjX7+w4jJgx
qUr7dT88l2RAYLHi+wMbSFyfRFOpYM7U5kbrjSrfWdBVsORmTyQn8BiapIaQYnlC
blbDGe09asXaXZ7HNAj1XmlB9qbRtYlVYx2hrTcNMAic8uMIHIwnFeqWhHLtfsER
KuM9TP+72Hy+z0p5a86kM1snvut8QbSxX5Kni1KLLQyw3M1KaH0MieAwiSVTV+Mh
6g02hjXlA7V3onIpbtPXYIzzV/uf4yvhT8iZOoPdCx/BePcHgccH4eoSH4ozGDGf
Hi9ghPB6Qi7gw1kzS3TANtuEx6UA+pruRHcTH5RbBIWSuXK5PuPZzaiAVObOSLA6
BoUc5XwW7O8RcSqeum1nkioTemc1xPwa734NmH2YIrJO9tdqkOUqNhkAPnkoQh57
KGxfo9wEGKCKGDiGNNfYMmp15KNMRstyL2InZEw67MIgLoPE/m/533D8aP7Wj7HQ
sUWWDnWB3UKLNg2JRkHGa2t/nQVSWfDHG2OndeHA2bZ3mqW3246OFXWO0IzAv/7I
JJCMWKSExqnDXQ1S5zmb88b+GXo69YWU+ZAd4HrtTAJoCxPH/hjkOwI0/oYH7N0/
wpNZo9gg
=etB6
-----END PGP SIGNATURE-----
--- End Message ---
__
This is the maintainer address of Debian's Java team
<https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-java-maintainers>.
Please use
[email protected] for discussions and questions.