Accepted:
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 29 Mar 2016 12:05:49 +0200 Source: libxstream-java Binary: libxstream-java Architecture: source all Version: 1.4.9-1 Distribution: unstable Urgency: medium Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> Changed-By: Emmanuel Bourg <ebo...@apache.org> Description: libxstream-java - Java library to serialize objects to XML and back again Closes: 819455 Changes: libxstream-java (1.4.9-1) unstable; urgency=medium . * New upstream release - Fixes CVE-2016-3674: XML External Entity vulnerability (Closes: #819455) - Ignore the new xstream-jmh module - Updated the Maven rules * No longer build the xstream-benchmark module (never used in Debian) * Build with maven-debian-helper * Depend on libcglib-nodep-java instead of libcglib3-java * Standards-Version updated to 3.9.7 (no changes) * Use secure Vcs-* fields * Updated the old references to codehaus.org Checksums-Sha1: 4cf4ec64900223bfa333836874027744232d8547 2392 libxstream-java_1.4.9-1.dsc 0495145c1d88722ee4331265a30ce93d5dab6bda 419660 libxstream-java_1.4.9.orig.tar.xz 1dbdca9aeee30d1d5f6e143103a9381cfc5c562d 6232 libxstream-java_1.4.9-1.debian.tar.xz 9afd8dacf870f8b4db79264868900bb91f95c5da 499872 libxstream-java_1.4.9-1_all.deb Checksums-Sha256: 3967f17b4675a4fce56e09a1620e27961652a023634875322bb3ebe9c1929702 2392 libxstream-java_1.4.9-1.dsc f97c2c723e03892859c69242397815a00b10ae1da0ca78d6c9b1f51397752c66 419660 libxstream-java_1.4.9.orig.tar.xz 7db86593bc736a00d87ee936af11e925c1ccbd37fb0dd63457dbf0407972b376 6232 libxstream-java_1.4.9-1.debian.tar.xz 94f28584d0e3fef8cf6fa81d29bce93107007787ff183713eb03a6025c068c27 499872 libxstream-java_1.4.9-1_all.deb Files: b2652b2d00e8de2f643097f1cc2be922 2392 java optional libxstream-java_1.4.9-1.dsc 259d2a02e54c3b6deb41fe2861f74d87 419660 java optional libxstream-java_1.4.9.orig.tar.xz 8e8386e823bf938d034334275c18144a 6232 java optional libxstream-java_1.4.9-1.debian.tar.xz 442e2b05d0c401f70c0f2032676da156 499872 java optional libxstream-java_1.4.9-1_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCAAGBQJW+l73AAoJEPUTxBnkudCsCVUP/03hGK1opaaLdbhgrMK41rFx O+HJk792poaRyXiOk8EQ1kM4YOeOacseLOq/YBEfCOAys2uSH6gi3GYydfINV7wM BOkBXGDUjas2PREl1nEXbORV+NQqsK9CfBvBa3TRcDosTiZ7EGP7HRTigYSJ/a2s 2onFr+b2g+7YhEU97Sn7sj1zLh5XOD7FdNenHSbQUlS/++FSmqCfIezdbzyPinsS RkP4oXtiglt6sTdj+vvvIiG3TfyoDhMn/QXu56WAfunOdG8JKSS5kk/YKh3jnG1c 8OxmwSZgrSJz4nqSiz81jA/lT43P1kx3CnKlAqmVjh9p4BCi3W81giOs21lH1D2s 7/SFniF+nSc/H/wqwhSKE6dEMiHMFxEAHe4juI3LVBmHRkdW49FboHDCWvYw0Vxu aqMVl2ehT6hamv4rTdCToLhgKtummrberPCqrmmfRLq0jT7ZLUHEcay9stqA7ckY gFQSoVCyRLnEDi/Mpdayj8Nxri4MpLeBDy7slCEjLfdWZBVSplpjRlXZbRiz4ec9 exEndrZCI4vwLkQcM1BIEDmqp4VabtIYc8sX7n1tg6NwVh592ftDtwjypLXSm+KV iTmrfcgmBJ1NQ4A9hVS2Wo3E8+3JvhWfHotwGcPOhQ4L1Fz5W+TrItx2Q8QoHDGn lNuuu13EmnnlwZWUBAW/ =QWIL -----END PGP SIGNATURE----- Thank you for your contribution to Debian. __ This is the maintainer address of Debian's Java team <http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-java-maintainers>. Please use debian-j...@lists.debian.org for discussions and questions.