-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Mon, 05 May 2024 11:33:57 +0100
Source: shim
Binary: shim-helpers-amd64-signed-template shim-unsigned
Architecture: amd64
Version: 15.8-1~deb11u1
Distribution: bullseye
Urgency: medium
Maintainer: amd64 / i386 Build Daemon (x86-csail-01) <buildd_amd64-x86-csail-01@buildd.debian.org>
Changed-By: Steve McIntyre <93sam@debian.org>
Description:
 shim-helpers-amd64-signed-template - boot loader to chain-load signed boot loaders (signing template)
 shim-unsigned - boot loader to chain-load signed boot loaders under Secure Boot
Closes: 1046268 1069054
Changes:
 shim (15.8-1~deb11u1) bullseye; urgency=medium
 .
   * New upstream release fixing more bugs
   * Remove all our previous patches, no longer needed:
     + Make-sbat_var.S-parse-right-with-buggy-gcc-binutils.patch (now
       upstream)
     + Enable-NX.patch (we don't want NX just yet until the whole boot
       stack is NX-capable)
     + block-grub-sbat3-debian.patch (not needed now upstream grub SBAT
       is 4)
   * Cherry-pick 2 new patches from upstream for grub revocations:
     + 0001-sbat-Add-grub.peimage-2-to-latest-CVE-2024-2312.patch
     + 0002-sbat-Also-bump-latest-for-grub-4-and-to-todays-date.patch
   * Log if the build is nx-compatible or not
   * Force shim to use the latest revocations by default to block some
     older grub / peimage issues. This is:
     "shim,4\ngrub,4\ngrub.peimage,2\n"
   * Install a copy of the Debian CA certificate into /usr/share/shim.
     Closes: #1069054
   * Clean up better after build. Closes: #1046268
Checksums-Sha1:
 5d36786a09dd54cc48e5d251f5d50bf81036a953 15412 shim-helpers-amd64-signed-template_15.8-1~deb11u1_amd64.deb
 a296865d3d0d1aaf7ac6112e0b63482ff0ca0924 442556 shim-unsigned_15.8-1~deb11u1_amd64.deb
 253f288b1870d0013415ba746cd4470eea809bd4 6820 shim_15.8-1~deb11u1_amd64-buildd.buildinfo
Checksums-Sha256:
 3346221cb9181e7a6962642ee8e52b17619f378d9de7e2456304c482a59f48fa 15412 shim-helpers-amd64-signed-template_15.8-1~deb11u1_amd64.deb
 06cf3b610acaff5f68f8f09a1005730de9c3740ddb54aab2f87a69b5efe12745 442556 shim-unsigned_15.8-1~deb11u1_amd64.deb
 07548b37c438ea0b73caba802384e209fb3a8d67a415610ae5eadff710c580e9 6820 shim_15.8-1~deb11u1_amd64-buildd.buildinfo
Files:
 e77e9604f754902ce2a2d2eb506a8ecd 15412 admin optional shim-helpers-amd64-signed-template_15.8-1~deb11u1_amd64.deb
 a1c75bec2190855a253cf9ef6dbfec14 442556 admin optional shim-unsigned_15.8-1~deb11u1_amd64.deb
 e822f2cd810c68bdac9c1462c4e55045 6820 admin optional shim_15.8-1~deb11u1_amd64-buildd.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEvy6d65NNYPbL6IQIEQ1nooK/IAQFAmY7xpcACgkQEQ1nooK/
IAQPOg/+LeswO9rhHQJ5mxvlk4jU3msQGT/Yhf1OgdoGmlY4dAQR70rJ+DTXQ2nl
O//YmpPNAbQfb9Pkml4hDXQZSiJjHrcF/FObSkI4FKjGT+b41y6R8aa8J6SyUFAJ
gDrgo3Weo1cknM//1G0bK0x+pemuqqVBuTKfQLCaht/0lJL8cVY55qspoWfPCj+1
SHZA7c32qh+983LKCJEa3pUkLww8EiC/7dL4YyosH7hkvNbeSQ1fldozWDpuZ9v5
aEnd2nnZ4BFPlFTq2rwCqRB8+sLz0txQFdUocZ9BiwCml3xCiWbxB/H8tT0xW5kL
EsA9Ov2NCjwlQi9mPZkDIkyOUSxZmD1IwQ13zpD3/4KHOf+PWzZW/OEVyqr6xgfh
FD9yl+v+DwSc3gwELaLlcbToPs8UQnxX3WEeNFPnTgZUmubpbN175PwbScMoVk2b
PTDlboU9VKkgcvGh1CQOpkhu9jOIFUy9ys3UrNPGX+GtxhAzTLbD5x8Ju4g1XZ6/
/QVoP2xKphovvbHBvjCJR+sfZq0GcKUkoXFAbss3mMwZhTCtqN3yGEuoi0vCfLZy
EYigtJu0F6Hlk1iEbekkF5g8JWiU4OdlCXbDB2CRSx1HQff7tn3XJqLrO2UfwGcg
v0QsoKUIW4EIthJ3vMvu4kXvx8CEpUweQL/OxXQvBu3iED3Mjg8=
=X/LC
-----END PGP SIGNATURE-----