Debian Patches

Status for fonttools/4.57.0-1+deb13u1

Patch Description Author Forwarded Bugs Origin Last update
0001-add-module-path-for-automodule-directive.patch add module path for automodule directive Hideki Yamane <henrich@debian.org> no 2017-08-28
0002-keep-doctest-compatible-with-Unicode-15.1.patch keep doctest compatible with Unicode 15.1
Revert changes made in
https://github.com/fonttools/fonttools/commit/10a61ef7de0f5c99f37584840641ee6c62dc74bd
before Debian packages support for unicode 16.0.
Boyuan Yang <byang@debian.org> not-needed 2024-10-19
Skip-test-on-i386-that-fails-because-of-excess-precision.patch Skip test on i386 that fails because of excess precision Jeremy BĂ­cha <jeremy.bicha@canonical.com> no 2024-11-20
0004-Disable-new-tests-related-to-unicode-16.0.patch Disable new tests related to unicode 16.0
Do not run tests introduced by
https://github.com/fonttools/fonttools/commit/b26271cc4dcc5256a2181d8307dde9a2b3cd45d5
before using Unicode 16.0.
Boyuan Yang <byang@debian.org> no 2025-04-05
0005-CVE-2025-66034.patch varLib: only use the basename(vf.filename)
Fontmake already does that since the beginning:
https://github.com/googlefonts/fontmake/blob/35e9e5dbdf2130a04c54688bb1bdbcfdb4b5fc67/Lib/fontmake/font_project.py#L438

it's safer to disallow path traversal as it may lead to abritrary file write vulnerability, see https://github.com/fonttools/fonttools/security/advisories/GHSA-768j-98cg-p3fv
Cosimo Lupo <clupo@google.com> no upstream, a696d5ba93270d5954f98e7cab5ddca8a02c1e32 2025-11-21

All known versions for source package 'fonttools'

Links