Free software activity in September 2026
My Debian contributions this month were all sponsored by Freexian.
You can also support my work directly via Liberapay or GitHub Sponsors.
OpenSSH
I worked with upstream to remove libselinux linkage from /usr/sbin/sshd.
I applied a fix from Mark Robillard Jr to fix reload logic when using sysvinit.
groff
I upgraded from 1.24.1 to 1.24.2, which fixed a few command injection security vulnerabilities.
parted
I upgraded from 3.7 to 3.8, which fixed CVE-2026-89085 and CVE-2026-89088.
Python packaging
New upstream versions:
- beaker (contributed supporting fix upstream)
- bitstruct
- cachelib
- dep-logic
- django-guardian
- django-oauth-toolkit (fixing use of an old Bootstrap version)
- django-polymorphic (contributed supporting fix upstream)
- djangorestframework (fixing CVE-2026-73228 and CVE-2026-73229)
- flask-security
- isort
- langtable
- magic-wormhole-mailbox-server (fixing use of
pkg_resources) - multipart
- nagiosplugin
- poetry-plugin-export
- proglog (fixing use of
pkg_resources) - prospector (fixing use of
pkg_resources) - pybind11-stubgen
- pydantic
- pydantic-core
- pytest-rerunfailures
- python-anyio (fixing CVE-2026-63349, CVE-2026-63374, and CVE-2026-64847 and a build failure on Python 3.15)
- python-asttokens
- python-asyncvarlink
- python-blockbuster (fixing a build failure on Python 3.15)
- python-btrees
- python-django-health-check
- python-django-otp
- python-django-simple-history
- python-email-validator
- python-forbiddenfruit
- python-ldap
- python-linuxnamespaces
- python-plaster-pastedeploy
- python-pydash
- python-pyzipper (fixing CVE-2026-44722)
- python-quart-trio
- python-rich-click (fixing harlequin)
- python-repoze.lru
- python-repoze.tm2 (fixing use of
pkg_resources) - python-time-machine
- python-urllib3 (filed upstream issue with recent Python 3.14 versions)
- python-vblf
- quart
- responses
- sphinx-autodoc-typehints
- storm (fixing a build failure with Python 3.15, which I helped to land upstream)
- trove-classifiers
- twine
- vdirsyncer
setuptools 84 is now in Debian and no longer contains pkg_resources. Removing uses of that module has been an ongoing project for a while now, but I did another batch of fixes this month:
- flufl.password
- junos-eznc
- python-decopatch
- python-launchpadlib
- python-plaster-pastedeploy
- python-pyramid-retry
- sphinxcontrib-log-cabinet
- sphinxcontrib-restbuilder
- straight.plugin
A new python-coverage version triggered several build regressions due to a known problem in pytest-cov. I worked around these by setting COVERAGE_CORE=ctrace:
Other build/test failures:
- afew
- django-downloadview
- django-filter
- django-polymorphic
- drf-haystack
- drf-yasg-nonfree
- pydantic-core
- pylint
- pytest-openfiles
- pytest-remotedata
- python-aiohttp-oauthlib
- python-cron-descriptor
- python-django-nh3
- python-graphene
- python-pydash
- python-pysolr
- python-time-machine
- python-vblf
- social-auth-core
- sphinx-book-theme
- tagpy: FTBFS against python 3.15rc2
- tagpy: TypeError: ‘include_dirs’ (if supplied) must be a list of strings
- typer
I investigated a build failure in python-proton-vpn-local-agent and proposed a fix upstream, but I’m not comfortable applying this in Debian without review. If you’re familiar with this code, please take a look.
I fixed some other bugs:
- python-pycudwt: Requires manual rebuild for python3.14-only transition
- python-testing.postgresql: Fails to build source after successful build
- tomopy: Requires manual rebuild for python3.14-only transition
- typer: Fails to build source after successful build
- vdirsyncer: Fails to build source after successful build
Rust packaging
rust-derivre had an invalid Section field, which I cleaned up.