| < January 2024 | Russ Allbery > Eagle's Path | July 2024 > |
For some time now, Debian has been discussing a possible enhancement to the way that Debian packages are uploaded to the archive. The basic idea is to allow a package upload to be triggered by pushing a signed tag, with some structured metadata, to Salsa, the instance of GitLab that Debian provides for packaging repositories. This would allow Debian package maintainers to use a more typical Git-first workflow, where releases are triggered by Git tags and the release artifacts are built in a clean CI environment, while still enforcing the existing Debian rules about who is allowed to upload packages.
As part of that effort, I recently completed a detailed security review of the tag2upload design. I sent it to debian-vote as part of the ongoing discussion, but have also posted it at the link above to give it a more permanent home.
This security review may be revised based on the discussion if people point out things that I missed.
This is a bug fix and minor feature release over INN 2.7.1, and the upgrade should be painless. You can download the new release from ISC or my personal INN pages. The latter also has links to the full changelog and the other INN documentation.
For the full list of changes, see the INN 2.7.2 NEWS file.
As always, thanks to Julien ÉLIE for preparing this release and doing most of the maintenance work on INN!
| < January 2024 | Russ Allbery > Eagle's Path | July 2024 > |