Please remove node-solid-keychain and node-trust-webcrypto source and binary packages from lunar

Bug #2003831 reported by Bryce Harrington
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
node-solid-keychain (Ubuntu)
Fix Released
Undecided
Unassigned
node-trust-webcrypto (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Please remove from the lunar archive:
  - node-solid-keychain/0.1.3-3.1 (source)
  - node-solid-keychain/0.1.3-3.1 (binary)
  - node-trust-webcrypto/0.9.2-1 (source)
  - node-trust-webcrypto/0.9.2-1 (binary)

node-trust-webcrypto and node-solid-keychain block the nodejs transition.
(C.f. https://people.canonical.com/~ubuntu-archive/proposed-migration/update_excuses.html#nodejs)

node-trust-webcrypto is a dependency of node-solid-keychain, but nothing else appears to depend on them in lunar:

  $ apt-cache rdepends node-trust-webcrypto
  node-trust-webcrypto
  Reverse Depends:
    node-solid-keychain
  $ apt-cache rdepends node-solid-keychain
  node-solid-keychain
  Reverse Depends:

Both of these are also failing Debian CI, with the same errors in test logs. Neither of these have had a release in a while, and they appear to be unmaintained. node-solid-keychain has been moved upstream out of the @solid/ namespace to @solid-contrib/ which seems to be causing its autopkgtest failures.

node-trust-webcrypto's upstream in particular includes an archiving notice:

https://github.com/anvilresearch/webcrypto/commit/210653f1bee449fec86214dc2fa4258fff775b4c

"# NOTICE # We’re archiving Anvil Connect and all related packages. This code is entirely MIT Licensed. You’re free to do with it what you want. That said, we are recommending _**against**_ using it, due to the potential for security issues arising from unmaintained software. For more information, see the announcement at [anvil.io](https://anvil.io)."

This seems a convincing point to me for removal of these two packages from the archive. As an unmaintained and out of date crypto package, users relying on it could be exposed to security issues that don't look likely to ever be addressed.

Bryce Harrington (bryce)
description: updated
Revision history for this message
Steve Langasek (vorlon) wrote :

Removing packages from lunar:
 node-solid-keychain 0.1.3-3.1 in lunar
  node-solid-keychain 0.1.3-3.1 in lunar amd64
  node-solid-keychain 0.1.3-3.1 in lunar arm64
  node-solid-keychain 0.1.3-3.1 in lunar armhf
  node-solid-keychain 0.1.3-3.1 in lunar i386
  node-solid-keychain 0.1.3-3.1 in lunar ppc64el
  node-solid-keychain 0.1.3-3.1 in lunar riscv64
  node-solid-keychain 0.1.3-3.1 in lunar s390x
Comment: autopkgtests fail, not in Debian testing, blocks nodejs transition; LP: #2003831
1 package successfully removed.

Changed in node-solid-keychain (Ubuntu):
status: New → Fix Released
Revision history for this message
Steve Langasek (vorlon) wrote :

Removing packages from lunar:
 node-trust-webcrypto 0.9.2-1 in lunar
  node-trust-webcrypto 0.9.2-1 in lunar amd64
  node-trust-webcrypto 0.9.2-1 in lunar arm64
  node-trust-webcrypto 0.9.2-1 in lunar armhf
  node-trust-webcrypto 0.9.2-1 in lunar i386
  node-trust-webcrypto 0.9.2-1 in lunar ppc64el
  node-trust-webcrypto 0.9.2-1 in lunar riscv64
  node-trust-webcrypto 0.9.2-1 in lunar s390x
Comment: autopkgtests fail, not in Debian testing, blocks nodejs transition; Debian bug #1002262, LP: #2003831
1 package successfully removed.

Changed in node-trust-webcrypto (Ubuntu):
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.