-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sat, 04 May 2024 21:28:21 +0100
Source: shim
Binary: shim-helpers-arm64-signed-template shim-unsigned
Architecture: arm64
Version: 15.8-1~deb12u1
Distribution: bookworm
Urgency: medium
Maintainer: arm Build Daemon (arm-conova-03) <buildd_arm64-arm-conova-03@buildd.debian.org>
Changed-By: Steve McIntyre <93sam@debian.org>
Description:
 shim-helpers-arm64-signed-template - boot loader to chain-load signed boot loaders (signing template)
 shim-unsigned - boot loader to chain-load signed boot loaders under Secure Boot
Closes: 936009 1046268 1069054
Changes:
 shim (15.8-1~deb12u1) bookworm; urgency=medium
 .
   [ Steve McIntyre ]
   * Cope with changes in pesign packaging.
   * New upstream release fixing more bugs
   * Remove all our previous patches, no longer needed:
     + Make-sbat_var.S-parse-right-with-buggy-gcc-binutils.patch (now
       upstream)
     + Enable-NX.patch (we don't want NX just yet until the whole boot
       stack is NX-capable)
     + block-grub-sbat3-debian.patch (not needed now upstream grub SBAT
       is 4)
   * Cherry-pick 2 new patches from upstream for grub revocations:
     + 0001-sbat-Add-grub.peimage-2-to-latest-CVE-2024-2312.patch
     + 0002-sbat-Also-bump-latest-for-grub-4-and-to-todays-date.patch
   * Log if the build is nx-compatible or not
   * Force shim to use the latest revocations by default to block some
     older grub / peimage issues. This is:
     "shim,4\ngrub,4\ngrub.peimage,2\n"
   * Install a copy of the Debian CA certificate into /usr/share/shim.
     Closes: #1069054
   * Clean up better after build. Closes: #1046268
 .
   [ Bastien Roucariès ]
   * Port autopkgtest from ubuntu
   * Import MR-12: "shim-unsigned:amd64 cannot be installed alongside
     shim-unsigned:i386", thanks to adrian15 adrian15 (Closes: #936009).
   * Fix debian/watch and check signature
Checksums-Sha1:
 a5946523d762ee6d3c2072fb69d84d58be3c2c62 11540 shim-helpers-arm64-signed-template_15.8-1~deb12u1_arm64.deb
 e175e930cc314a478ef18e2b8f49023c56d727d9 409952 shim-unsigned_15.8-1~deb12u1_arm64.deb
 65f0d90453f3e6b2f2282f09db8490e5e0aff8fe 6845 shim_15.8-1~deb12u1_arm64-buildd.buildinfo
Checksums-Sha256:
 523d8afcd87ec3a16e74c6661fa726ef3a281c737d46eabbd716e8d195c916b8 11540 shim-helpers-arm64-signed-template_15.8-1~deb12u1_arm64.deb
 b06d659122f162f95e397adf936a93b0a9c7cd993e4ba353159df2fb3b5cb720 409952 shim-unsigned_15.8-1~deb12u1_arm64.deb
 27d6687894b8b71a2101f982d6231686c14602d4d7c46a2e2ce03f339a77b8f5 6845 shim_15.8-1~deb12u1_arm64-buildd.buildinfo
Files:
 cb7a8575b5997ff4a850682a47e98ce6 11540 admin optional shim-helpers-arm64-signed-template_15.8-1~deb12u1_arm64.deb
 842767fa18c3681502ca82f1877f58fa 409952 admin optional shim-unsigned_15.8-1~deb12u1_arm64.deb
 6ec649131c72c45655eb45d94491ee2f 6845 admin optional shim_15.8-1~deb12u1_arm64-buildd.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEU81tY/BC8e+eAeWhLffeOnPnbLUFAmY7xrUACgkQLffeOnPn
bLUf8A/8C/7jZteXtCaNQs810qMn6krdQmRueOgqQGqEp2wWVRKS/vN8wqyEBeID
vqKJbewqxUvngIKVk6JWU7mLt642YFBkli877LrD0bM/Q2OtKkVxYIJhreon0r6A
vD0FeaVIsiK8DQGjdjux1xSS1W514Q6JJtLbGepvkfe6INVWbwoSWK0SPxsfdeJ8
golo7aHjUx/8T3ulwJD1aGkij1FvFOD4ikCo5jioera2Seowx0V5J7X3MBAMWGXa
mTPTYMd3yCnmP0RvLM4pFjktvRGa2KGsGYKg+Rwf8FTfabz7sGQoDHICH697bSjV
6HV8MZ3nnJiMIje/MuSo3BpnG3xiy5r/3IT88EVfdwPIQhra6pAnsWTga6UmSY7V
/7/891rVMqLC+A7CI3rRb+Fgvs+JkiMg/SzhbHo1Db7NfHzv/abOMBqhIhoCXmKV
T0aPtkAa1vUaWbumMXoVixuwXp+qZcV4kTpFuMPOsFpBXlZrWG6Kmpymd1LrzkBq
JYMKlxXEswSmkjWd4nmAq/OOERsi+mcb+IDCGBxZdJwlLtoitltHC1Z+bCKB9tnY
KJmxD6Wn+pGkWbOHSQT+Q205Klm1W9I4um+yGko9bAOR+GQbN+3g63KjyApTbrtp
0RnBdgBmXUP79DD5wY078KY5BI4Dvhj4l8leYRU1y6hLYtmrHpA=
=j2db
-----END PGP SIGNATURE-----