Debian Patches

Status for golang-github-notaryproject-notation-go/1.3.2-4

Patch Description Author Forwarded Bugs Origin Last update
0001-Fix-overflow-on-32-bit-architectures.patch Fix overflow on 32-bit architectures
On 32-bit architectures, math.MaxInt64 overflows int in VerifyOptions.MaxSignatureAttempts.
Use math.MaxInt instead.
Reinhard Tartler <siretart@tauware.de> yes upstream upstream, https://github.com/notaryproject/notation-go/commit/a48f22835cb593d4a8ab6032f141a64de01e278d 2026-09-25
0002-Allow-skipping-tests-that-connect-to-the-internet.patch Allow skipping tests that connect to the internet
In isolated or offline build environments (such as Debian package build
chroots), tests that attempt DNS lookups or external TCP connections fail.
Skip the test when dialing external hosts fails.
Reinhard Tartler <siretart@tauware.de> not-needed debian 2026-09-25
0003-Skip-tests-that-fail-on-unknown-certificate-status.patch Skip tests that fail on unknown certificate status
In offline build environments, authentic timestamp verification cannot
reach OCSP or CRL revocation endpoints over the internet, causing tests
to fail with "revocation status is unknown". Skip the subtests when this
revocation error occurs.
Reinhard Tartler <siretart@tauware.de> not-needed 2026-09-25
0004-disable-network-tests.patch Disable network tests
Disable TestSignWithTimestamping which attempts to access timestamping
authorities over the internet, failing in offline build environments.
Santiago Vila <sanvila@debian.org> not-needed debian 2026-09-25
0005-Fix-mockRemoteClient-blob-upload-Location.patch Fix mockRemoteClient to return valid Location and Request matching registry host

In oras-go >= 2.6.2 (GHSA-jxpm-75mh-9fp7), blob upload location validation
requires the Location header to match the registry host. Because
mockRemoteClient previously returned an http.Response with an empty
Request and a relative Location ("test"), Location() could not resolve
the host, leading to test failures in TestPushSignature and
TestPushSignatureImageManifest.

Passing the original req as Response.Request and providing a valid
Location path under /v2/test/blobs/uploads/ allows Location() to resolve
properly against the request URL and pass host validation in oras-go.
Reinhard Tartler <siretart@tauware.de> yes debian upstream 2026-09-25
0006-Escape-double-quotes-in-test-DN-per-RFC-4514.patch Escape double quotes in test DN to comply with RFC 4514
In go-ldap >= 3.4.14, unescaped double quotes in DN strings are strictly
rejected per RFC 4514 Section 2.4. In the Go string literal for validDN3,
`\"` produced an unescaped literal `"` in the DN string rather than an escaped
quotation mark `\"`, causing parsing to fail with `got unescaped character: '"'`.

Escaping the double quotes properly as `\\\"` ensures validDN3 represents a
valid RFC 4514 DN.
Reinhard Tartler <siretart@tauware.de> yes debian 2026-09-25

All known versions for source package 'golang-github-notaryproject-notation-go'

Links