-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 26 Mar 2026 14:45:00 +0100 Source: simpleeval Binary: python3-simpleeval Architecture: source all Version: 0.9.12-1+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: Debian Tryton Maintainers Changed-By: Mathias Behrle Description: python3-simpleeval - Simple, safe single expression evaluator library (Python 3) Changes: simpleeval (0.9.12-1+deb12u1) bookworm-security; urgency=high . * Add 01_CVE-2026-32640.patch. This patch fixes CVE-2026-32640 https://github.com/danthedeckie/simpleeval/pull/171 with commits https://github.com/danthedeckie/simpleeval/commit/9cb4a7b99498c173263bd90f77bc185e160fb6b8 https://github.com/danthedeckie/simpleeval/commit/1654cbf0219345f707c79664b8657be6b8d23e33 https://github.com/danthedeckie/simpleeval/commit/cffa9f68cee54404a2ef43d949a8ae8a3311c503 * Add a salsa-ci.yml targeting bookworm. Checksums-Sha1: 8d31f1f2239c2446a95891d42869bc372305fd4f 2205 simpleeval_0.9.12-1+deb12u1.dsc b89811927cff618f9000e311a6facf8fa7831093 22693 simpleeval_0.9.12.orig.tar.gz d33497c89e15a50a40ecee694aa7be9c7ea40192 8684 simpleeval_0.9.12-1+deb12u1.debian.tar.xz 1c77b78b64ecc0dbb60d8cf77e143d652937e936 24636 python3-simpleeval_0.9.12-1+deb12u1_all.deb e2ad8d227db5af0102bac7e954d9770730bca05f 7497 simpleeval_0.9.12-1+deb12u1_amd64.buildinfo Checksums-Sha256: f4dce5e731b6f6985d4270c49e80c5fcfcc3d2fe655d67186e0758d63f02ac78 2205 simpleeval_0.9.12-1+deb12u1.dsc 3e0be507486d4e21cf9d08847c7e57dd61a1603950399985f7c5a0be7fd33e36 22693 simpleeval_0.9.12.orig.tar.gz 578ebc5f01908966255764cefa72f246a48e768b276ef46b25ba88fa3da8425b 8684 simpleeval_0.9.12-1+deb12u1.debian.tar.xz 8c0b587c0787aa1cfba796be6e4db2840ccf378f01fe14de5db34634891b230b 24636 python3-simpleeval_0.9.12-1+deb12u1_all.deb 2025897341c156fac40ad4466964eedcbe543a1463a715ba89d8e01757e51ace 7497 simpleeval_0.9.12-1+deb12u1_amd64.buildinfo Files: 3ab2d5af5d57d003324963fb3436094d 2205 python optional simpleeval_0.9.12-1+deb12u1.dsc e96cf00b108e79eb2be1b2587d3a9217 22693 python optional simpleeval_0.9.12.orig.tar.gz 03b9cf302b0cdb679ce27a1fbc799243 8684 python optional simpleeval_0.9.12-1+deb12u1.debian.tar.xz 7feaab3a5017db9449df438898d12d50 24636 python optional python3-simpleeval_0.9.12-1+deb12u1_all.deb f77d905a7e290dca227fa42e9fd73d1d 7497 python optional simpleeval_0.9.12-1+deb12u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- Comment: Signed by Mathias Behrle iQJFBAEBCgAvFiEErCl+XEa50LYccXaB1tCb5IQFu/YFAmnFS3oRHG1hdGhpYXNi QG05cy5iaXoACgkQ1tCb5IQFu/Z7jw//RJOZh7xFk8ntxzHwTK2m8GVDQR581E3k CPPBrtjVzT1JIU1mC6C6VY23XtwNpTcntu8s9pbMlIVQ/Oy0cRXdXZsstxkWmS6v c0XOWHG79sKRAZpjSOlI/cu2xVov8qj7pK0QT+vznNYsJqMnjl3zK3eWxP83p1zv zd2SIonucpO0OVimMpi/TB0+p+1cbv82iVC0ihTNtNUCGOTFGqkH2ec5UTvdfrNy 8Cgm/GH2wpTBVQMvRvKJMzn/oZg3IpBdmj8kUPKSV3Se+tQidja7RPE2NTneRIij yNi3NkE27TU7JwXSwQLWaa3dWzamN8WN2Umz6OE7NDg+VQBSDf4x/WPl1Iy0Fr9w SxufaRPJK1ebGKTqx9SrhbOv5quIOQ0mV2g2BHT2+xApztwqbtAE0MDKYUkSco2U /fsebG1Ru2F3LpzpXXIT5YoG3AUB3ia+0g8j8PhC36yT5B7q73J+FJcz31XykSe6 2FrL5Abr4qwRtTapCW1H9anSe2mwXzvejH3oLZt0qLddAoeJ+SjZQXM/7idyT54K 5gjVN/MtcFZ4UzFa3TzRiEKFdXCfI597xuwn0f12OL2tXtlXyE4n8bOYT/Vmzb3Q 3wHpD3a/DcsDuKQDaH11dpTcbAZbve0/8+K82hzLVM9YGu1QPNMSKMqQGRxfterC mH/hJXkbYIk= =x1h3 -----END PGP SIGNATURE-----