Your message dated Tue, 03 Nov 2015 10:24:49 +0000
with message-id <[email protected]>
and subject line Bug#800996: fixed in wagon2 2.10-1
has caused the Debian Bug report #800996,
regarding wagon2: depends on obsolete libcommons-httpclient-java library
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
800996: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=800996
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: wagon2
Severity: normal
User: [email protected]
Usertags: oldlibs libcommons-httpclient-java
Hi,
wagon2 depends on libcommons-httpclient-java, which is obsolete and was
replaced by libhttpclient-java. It has reached EOL status in 2011! It is no
longer supported upstream [1] and was affected by multiple security issues in
the recent past. wagon2 should be ported to the new libhttpclient-java
version, so that we can remove the old, unmaintained one. Please forward this
issue upstream, if you can't migrate the package yourself.
We would like to see libcommons-httpclient-java removed during the Stretch
release cycle but due to the large number of reverse-dependencies the outcome
depends more than ever on your help.
Please help us to accomplish this goal. We will bump this issue to important
when the list of rdeps is getting smaller and we think that the removal is
possible. We will eventually raise the severity to serious when the number
of rdeps is small.
If you have any questions don't hesitate to ask and contact us on
[email protected]
Regards,
Markus
[1] https://hc.apache.org/httpclient-3.x/
[2]
https://security-tracker.debian.org/tracker/source-package/commons-httpclient
--- End Message ---
--- Begin Message ---
Source: wagon2
Source-Version: 2.10-1
We believe that the bug you reported is fixed in the latest version of
wagon2, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Emmanuel Bourg <[email protected]> (supplier of updated wagon2 package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.8
Date: Tue, 03 Nov 2015 09:46:06 +0100
Source: wagon2
Binary: libwagon2-java
Architecture: source all
Version: 2.10-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Java Maintainers
<[email protected]>
Changed-By: Emmanuel Bourg <[email protected]>
Description:
libwagon2-java - resources' transport abstraction that is used in Maven
Closes: 800763 800996
Changes:
wagon2 (2.10-1) unstable; urgency=medium
.
* Team upload.
* New upstream release
* Depend on libcommons-net-java instead of libcommons-net2-java
(Closes: #800763)
* No longer build wagon-webdav-jackrabbit (never used in Debian)
(Closes: #800996)
Checksums-Sha1:
6fd415572fbdfec268723e95e6e5ebd1fd15f315 2813 wagon2_2.10-1.dsc
31bc41582242d894289b0e9e281dfc42ce77a40a 178384 wagon2_2.10.orig.tar.xz
47995a44a9779b03e55e4ac535f459a7eb6135e8 7200 wagon2_2.10-1.debian.tar.xz
29fe1fc7143aa124b824b6376f6eeffbc7637f78 2145028 libwagon2-java_2.10-1_all.deb
Checksums-Sha256:
d82fa773b1d1c08220913169f74f5db98daff7d9698476ac5018d76fcc8e2c9d 2813
wagon2_2.10-1.dsc
eb032481f0d1ab33f44d003df55d56ad8af8fcfae3c5d252f69ca10aa091f563 178384
wagon2_2.10.orig.tar.xz
aad6ff2d7ecc0880a4b7339c25dab416d737e432b4f49f750673fca41eb779a8 7200
wagon2_2.10-1.debian.tar.xz
1e63cfc012a87c70c7b6f3c3f5cb4d0cec7a1f3fc7d8406908e0b6deedc8b371 2145028
libwagon2-java_2.10-1_all.deb
Files:
aa30278dc18615563ebaefaf9ff3ebc9 2813 java optional wagon2_2.10-1.dsc
5ece65851b9894fd6ce392db28153691 178384 java optional wagon2_2.10.orig.tar.xz
38e9a9d33fcb2a57d621403db7edc843 7200 java optional wagon2_2.10-1.debian.tar.xz
0ef7d89d44a0ed5c015634ff8b29d09f 2145028 java optional
libwagon2-java_2.10-1_all.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBAgAGBQJWOIL0AAoJEPUTxBnkudCsZ1QP/i4IF2aLVGmvzxA3LGkAHhTC
SO8C7vDkfhl/RvEtSPlZ2Y1LZI+kbgXKQBqq85GFfk48I0iQS7I6etu4QwR5bDp4
MGqShweQli19V8ooSmPoBoDA0aF5Qcb0FqOj3Nb27TGpVJ74KOMUG8Ck4CdIjXu9
JlV/CMw7sc+2Dzyg4cmT9e0x52ngAgTQgwOKgEvStztf6djMSkMO6uvYkVoH3QI4
ieg8rIbkO7A7oLlr846n7eT+gsj4eJRIgQETEK6RSSctrvU6mWQ+NNiri4u0GOHc
7T7IBMelEhWCcj/wLauduy8sgUNLkYXQm1KFCvJpvLcdgESRGOUWJsy8NLduEp2q
VbElB5xrNr5sxGUYEA50e+VKk7qhcNUe+SfUKjFusmYrpdjAoAmIFaBoh+3HQbuk
WgzI+XQbIDLjFouafl0oCPNIOfb23TmsRr17MObgubhhBPmNzKiRGb2Nyk6gTmNu
ZRiVH93MIo07Yz7M582psTpXux2gbB53ikjKaJ9Laqb0+GoCwnhDtXvyacLLi0hs
nB9N2ojhzUquLuzsP8njjj/apSQxthro9NW6ClItsTdif5HLIxKBMImmSh4OFbyS
MPMzflcIB9TB5NVwiXdyUghnF3jgNB2mNLpXUYDnEauxIf/xTba5pDqgPadP40eC
tZO3XWz2U/dKWKP1jCct
=57gL
-----END PGP SIGNATURE-----
--- End Message ---
__
This is the maintainer address of Debian's Java team
<http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-java-maintainers>.
Please use
[email protected] for discussions and questions.