flatpak (1.18.4-1) unstable; urgency=high . * New upstream security fix release (Closes: #1149218) - Fix two related symlink traversal vulnerabilities to prevent arbitrary file deletion and limited file overwriting outside the deploy directory, and harden related code paths against symlink traversal (deletion: CVE-2026-97023, GHSA-5p67-xh8x-rq54) (overwriting: CVE-2026-97024, GHSA-8xgq-v545-vgvf) - Don't write authentication token to disk when using OCI remotes (CVE-2026-97025, GHSA-7rvf-rqr3-43j4) - Restrict permissions of temporary directories /var/tmp/flatpak-cache-* (CVE-2026-97026, GHSA-r9w3-qx54-qvc8) - Filter D-Bus .service files and freedesktop.org .desktop files with an allowlist to prevent denial of service and possibly sandbox escape (CVE-2026-97027, GHSA-v64f-hrwr-j4vh) - Prevent sandboxed processes from killing a parent process outside the sandbox (CVE-2026-97029, GHSA-f3p8-vr7v-gxf2) freerdp3 (3.32.1+dfsg-1) unstable; urgency=medium . * new upstream regression and bugfix release. After the latest hardening a few corner cases were not covered by regression tests and needed adjustment. Most notably fragmented static channel PDU were rejected breaking copy & paste for larger data. Security fixes: - https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-9qqc-m43j-g4r2 - https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3m9q-g533-rqjq - https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-262p-h989-vmpv - https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-5xjc-c64q-m8r6 - https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-f3vg-h45x-6wgf - https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-c49c-xm94-5qf3 fwupd (2.1.8-1) unstable; urgency=medium . [ Simon McVittie ] * d/rules: Explicitly enable docs if wanted, or disable if not * d/control, d/rules: Enable gir dh sequence declaratively * d/control: Build-Depend on required gir1.2-*-dev packages * d/control: Replace libgirepository1.0-dev B-D, again (Closes: #1118817, #1144572) . [ Mario Limonciello ] * New upstream version (2.1.8) r-cran-combinat (0.0-9-1) unstable; urgency=medium . * Team upload. * New upstream version * Use uscan v5 $template template. (routine-update) * Standards-Version: 4.7.4 (routine-update) * Remove NAMESPACE patch. * Restrict to R packages team core architectures (routine-update) * Drop 'Rules-Requires-Root: no' from d/control (routine-update) * Replace FSF postal address with a reference to https://www.gnu.org/licenses/. * lintian-brush: add d/u/metadata (routine-update) r-cran-pbapply (1.7-5-1) unstable; urgency=medium . * Team upload. * Packaging update (routine-update) * Use uscan v5 $template template. (routine-update) * New upstream version * Restrict to R packages team core architectures (routine-update) * Replace FSF postal address with a reference to https://www.gnu.org/licenses/. REMOVED: golang-github-mitchellh-go-linereader 0.0~git20190213.1b945b3-3 REMOVED: golang-github-timberio-go-datemath 0.1.0+git20200323.74ddef6-3 REMOVED: node-egjs-hammerjs 2.0.17-2 REMOVED: golang-github-approvals-go-approval-tests 0.0~git20180620.6ae1ec6-2 REMOVED: golang-github-phpdave11-gofpdi 1.0.13-2