Package: age
Version: 1.0.0~rc1-2+b3
Severity: important
X-Debbugs-Cc: fili...@ml.filippo.io

Dear Maintainer,

We recently published upstream v1.0.0 of age. There are some important changes
since v1.0.0-rc.3: a bug was fixed that would cause a percentage of armored 
files
to become corrupted; ssh-rsa keys too small to be secure are now rejected; a
limit on the number of recipients in a file has been lifted; and a few more.

The release also includes comprehensive manual pages.

We'd like to see v1.0.0 imported into testing, but would also like to see the
important bugs fixed in Debian 11.1. These bugs can cause data loss or 
significant
confusion since the version of age in Debian would refuse to decrypt valid 
files.

We prepared a branch of backports for Debian 11.1, in case v1.0.0 is deemed too
large a change to import. https://github.com/FiloSottile/age/commits/debian/11

Thank you,
Filippo

-- System Information:
Debian Release: 11.0
  APT prefers stable-security
  APT policy: (500, 'stable-security'), (500, 'stable')
Architecture: arm64 (aarch64)

Kernel: Linux 5.10.47-linuxkit (SMP w/4 CPU threads; PREEMPT)
Kernel taint flags: TAINT_OOT_MODULE, TAINT_RANDSTRUCT
Locale: LANG=C, LC_CTYPE=C.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /bin/dash
Init: unable to detect

Versions of packages age depends on:
ii  libc6  2.31-13

age recommends no packages.

age suggests no packages.

-- no debconf information

Reply via email to