-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sat, 04 May 2024 21:28:21 +0100
Source: shim
Binary: shim-helpers-amd64-signed-template shim-unsigned
Architecture: amd64
Version: 15.8-1~deb12u1
Distribution: bookworm
Urgency: medium
Maintainer: all / amd64 / i386 Build Daemon (x86-conova-01) <buildd_amd64-x86-conova-01@buildd.debian.org>
Changed-By: Steve McIntyre <93sam@debian.org>
Description:
 shim-helpers-amd64-signed-template - boot loader to chain-load signed boot loaders (signing template)
 shim-unsigned - boot loader to chain-load signed boot loaders under Secure Boot
Closes: 936009 1046268 1069054
Changes:
 shim (15.8-1~deb12u1) bookworm; urgency=medium
 .
   [ Steve McIntyre ]
   * Cope with changes in pesign packaging.
   * New upstream release fixing more bugs
   * Remove all our previous patches, no longer needed:
     + Make-sbat_var.S-parse-right-with-buggy-gcc-binutils.patch (now
       upstream)
     + Enable-NX.patch (we don't want NX just yet until the whole boot
       stack is NX-capable)
     + block-grub-sbat3-debian.patch (not needed now upstream grub SBAT
       is 4)
   * Cherry-pick 2 new patches from upstream for grub revocations:
     + 0001-sbat-Add-grub.peimage-2-to-latest-CVE-2024-2312.patch
     + 0002-sbat-Also-bump-latest-for-grub-4-and-to-todays-date.patch
   * Log if the build is nx-compatible or not
   * Force shim to use the latest revocations by default to block some
     older grub / peimage issues. This is:
     "shim,4\ngrub,4\ngrub.peimage,2\n"
   * Install a copy of the Debian CA certificate into /usr/share/shim.
     Closes: #1069054
   * Clean up better after build. Closes: #1046268
 .
   [ Bastien Roucariès ]
   * Port autopkgtest from ubuntu
   * Import MR-12: "shim-unsigned:amd64 cannot be installed alongside
     shim-unsigned:i386", thanks to adrian15 adrian15 (Closes: #936009).
   * Fix debian/watch and check signature
Checksums-Sha1:
 6aaf164f8c6fd8fde4bf10f0d567436bdccad518 11528 shim-helpers-amd64-signed-template_15.8-1~deb12u1_amd64.deb
 109cb3e6cd07c89034c7a12c63e8505fb85393c0 440260 shim-unsigned_15.8-1~deb12u1_amd64.deb
 178b290043e7fbea5d028d5bf3644bac22340af4 6846 shim_15.8-1~deb12u1_amd64-buildd.buildinfo
Checksums-Sha256:
 4cd91b5bbd81e277d98d9da4bd8f72833100e225f774d33185fb9118fa4c8c2a 11528 shim-helpers-amd64-signed-template_15.8-1~deb12u1_amd64.deb
 97e810e1f55cb7f9361a02e06c5adb5385a71c2586c9254184a545f04473fa9e 440260 shim-unsigned_15.8-1~deb12u1_amd64.deb
 eea9e55b0bd22e34e076e64745af4e1c1d11a97833224aae0c6ada8661610245 6846 shim_15.8-1~deb12u1_amd64-buildd.buildinfo
Files:
 52fcb4662f5f9175b385e50f1067890a 11528 admin optional shim-helpers-amd64-signed-template_15.8-1~deb12u1_amd64.deb
 b4189c307006e5159d2edac72d6a8b5a 440260 admin optional shim-unsigned_15.8-1~deb12u1_amd64.deb
 d08c4596fe590d451d15527e832e145b 6846 admin optional shim_15.8-1~deb12u1_amd64-buildd.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEgdRoRGwEM09wlaMzOni7ZmUpKEcFAmY7xrsACgkQOni7ZmUp
KEci9A/7BNzMBoE89YTfHLbustLMCmq+jnpv9UcyRIfYST59Et/H3Swmj0sgFVUM
lLeMXM6vuPA2SXffrE/b7CqfJlc/3LAm6xtDsmoJI/n5dmNhVCwY9tcUdjyAwVmv
4xNzknal4oWBJOAN3/bi+kn6gb6Zk42URLqFG8X9AsCTfUV1PZ/0WQCGoEeJC7vm
gILTaZQ8gTGQl8tcGrM8rTgOnPcHAKIhFeXIp8eqc+58KOyYPTpaOjv2pMLyQDS3
xrI/NSpU2pwtOhvr42/SBQ4bYhUMdfnQEwVWE8IswTsriqraRc+FYnOw6xIl6LlO
w0q9aRDqov7tXQix2H6r8h6zGhKNwp9T2JFAzc7MBhgfF9lv8dWi8SVaf22JlI2+
flu92tQJExCRs9YFLj8FuqNNczDxxGwHrEF+WPONig280r16qWQHw4msysS/6iAO
hwpi5ONb1GHQoTvMzbJD12lR0U/klativ+8q/zNV+wOtVL8EnB+spFUZNJy6DhMB
vpURvW+c8Iy85dNBV328fCO8OvJmur9vMftIjK5iuS4KWrq4oI4QuZsQ1rG3qSSu
ev1PA+W9kceybyGFJtIWihzWp6+chqLNMO51lH5rTX1kg2m7MP0Rn61hEjO8J/rn
CY9AGYYxu6smOsRh8ZKXE5uk72CnBka6/UZAwlO0DD0E7zNpX3I=
=aBBg
-----END PGP SIGNATURE-----