Merge tidy-html5 from Debian unstable for oracular

Bug #2064474 reported by Bryce Harrington
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
tidy-html5 (Ubuntu)
New
Undecided
Lena Voytek

Bug Description

Upstream: tbd
Debian: 2:5.6.0-11 2:5.8.0-1~exp2
Ubuntu: 2:5.6.0-11ubuntu2

Debian new has 2:5.8.0-1~exp2, which may be available for merge soon.

If it turns out this needs a sync rather than a merge, please change the tag 'needs-merge' to 'needs-sync', and (optionally) update the title as desired.

If this merge pulls in a new upstream version, also consider adding an entry to the Oracular Release Notes: https://discourse.ubuntu.com/c/release/38

### New Debian Changes ###

tidy-html5 (2:5.6.0-11) unstable; urgency=medium

  * Rebuild for Ubuntu 20.04 LTS.

  [ Debian Janitor ]
  * Drop no longer supported add-log-mailing-address setting from
    debian/changelog.
  * Use secure URI in Homepage field.
  * Set upstream metadata fields: Bug-Database, Repository, Repository-
    Browse.
  * Update standards version to 4.4.1, no changes needed.

 -- Boyuan Yang <email address hidden> Thu, 02 Jan 2020 13:22:18 -0800

tidy-html5 (2:5.6.0-10) unstable; urgency=medium

  * Rebuild for Debian Buster.

  [ Boyuan Yang ]
  * debian/control:
    + Bump debhelper compat to v12.
    + Bump Standards-Version to 4.3.0.

  [ Viktor Szépe ]
  * debian/control: Fix grammar in package description.

 -- Boyuan Yang <email address hidden> Thu, 28 Feb 2019 16:14:05 -0500

tidy-html5 (2:5.6.0-9) unstable; urgency=medium

  * debian/patches:
    - Drop debian-specific patch to revert issue-679 patch,
      libhtml-tidy-perl has made a new upload to address the
      issue downstream.
    + Cherry-pick upstream patch for upstream issue-697 and
      issue-712 (5.7.10 and 5.7.11 fix).
  * debian/symbols:
    + Add a Build-Depends-Package field as suggested by lintian.

 -- Boyuan Yang <email address hidden> Thu, 15 Nov 2018 19:58:50 -0500

tidy-html5 (2:5.6.0-8) unstable; urgency=medium

  * debian/patches:
    + Rearrange patch series to follow upstream commit order.
    + Add a patch to partially revert upstream issue-679 patch to avoid
      an unnecessary breaking behaviour for css-prefix. This fixes an
      autopkgtest regression in libhtml-tidy-perl.

 -- Boyuan Yang <email address hidden> Thu, 15 Nov 2018 11:08:12 -0500

tidy-html5 (2:5.6.0-7) unstable; urgency=medium

  * debian/rules:
    + Apply build workaround to fix FTCBFS due to man page generation.
      (Closes: #875429).
  * debian/control:
    + Drop useless ${shlibs:Depends} substitution from libtidy-dev's
      build dependency list.
  * debian/patches:
    + Cherry-pick several upstream trunk patches till tidy-html5 5.7.8.
      (Upstream 5.7.9 changeset is implemented in Debian-specific patch)

 -- Boyuan Yang <email address hidden> Wed, 14 Nov 2018 22:15:20 -0500

tidy-html5 (2:5.6.0-6) unstable; urgency=medium

  [ Ondřej Surý ]
  * Fix my email in d/control

  [ Dmitry Shachnev ]
  * Revert upstream commit that causes issues in python-tidylib.

 -- Ondřej Surý <email address hidden> Sat, 27 Oct 2018 18:52:51 +0000

tidy-html5 (2:5.6.0-5) unstable; urgency=medium

  * Revert 'Downgrade the debhelper compat level to 9'
    + Bump debhelper compat to v11.
  * Fix full library path (Closes: #911915)

 -- Ondřej Surý <email address hidden> Fri, 26 Oct 2018 06:38:07 +0000

tidy-html5 (2:5.6.0-4) unstable; urgency=medium

  * Rebuild for all architectures on Debian Buildds.
  * debian/patches: Cherry-pick some important fixes from trunk:
    + Fix unsafe use of output buffer as input param (Upstream issue 655)
    + Fix typo in TidyHideComments description (Upstream issue 684)

 -- Boyuan Yang <email address hidden> Thu, 25 Oct 2018 11:13:45 -0400

tidy-html5 (2:5.6.0-3) unstable; urgency=medium

  * Downgrade the debhelper compat level to 9
  * Change the SONAME bump to 5deb1
  * Add Boyuan Yang to Uploaders
  * [CVE-2017-17497]: Add upstream fix for segmentation fail on NULL node in loop

 -- Ondřej Surý <email address hidden> Fri, 19 Oct 2018 08:32:17 +0000

### Old Ubuntu Delta ###

tidy-html5 (2:5.6.0-11ubuntu2) noble; urgency=high

  * No change rebuild for 64-bit time_t and frame pointers.

 -- Julian Andres Klode <email address hidden> Mon, 08 Apr 2024 18:20:59 +0200

tidy-html5 (2:5.6.0-11ubuntu1) noble; urgency=medium

  * SECURITY UPDATE: arbitrary code exec via recursive parsing
    - debian/patches/CVE-2021-33391-pre1.patch: introduce stack functions
      in src/lexer.c, src/lexer.h.
    - debian/patches/CVE-2021-33391.patch: refactor the recursion into a
      loop with a heap-based stack in src/gdoc.c.
    - CVE-2021-33391

 -- Marc Deslauriers <email address hidden> Fri, 10 Nov 2023 10:57:54 +0200

tidy-html5 (2:5.6.0-11build2) jammy; urgency=high

  * No change rebuild for ppc64el baseline bump.

 -- Julian Andres Klode <email address hidden> Fri, 25 Mar 2022 10:58:54 +0100

tidy-html5 (2:5.6.0-11build1) impish; urgency=medium

  * No-change rebuild to build packages with zstd compression.

 -- Matthias Klose <email address hidden> Thu, 07 Oct 2021 12:25:38 +0200

Bryce Harrington (bryce)
Changed in tidy-html5 (Ubuntu):
milestone: none → ubuntu-24.06
Lena Voytek (lvoytek)
Changed in tidy-html5 (Ubuntu):
assignee: nobody → Lena Voytek (lvoytek)
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.