{
    "summary": {
        "snap": {
            "added": [],
            "removed": [],
            "diff": []
        },
        "deb": {
            "added": [],
            "removed": [],
            "diff": [
                "libexpat1:riscv64",
                "libxml2-16:riscv64",
                "rsyslog",
                "rust-coreutils"
            ]
        }
    },
    "diff": {
        "deb": [
            {
                "name": "libexpat1:riscv64",
                "from_version": {
                    "source_package_name": "expat",
                    "source_package_version": "2.7.4-1",
                    "version": "2.7.4-1"
                },
                "to_version": {
                    "source_package_name": "expat",
                    "source_package_version": "2.7.4-1ubuntu0.1",
                    "version": "2.7.4-1ubuntu0.1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-32776",
                        "url": "https://ubuntu.com/security/CVE-2026-32776",
                        "cve_description": "libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-16 14:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-32777",
                        "url": "https://ubuntu.com/security/CVE-2026-32777",
                        "cve_description": "libexpat before 2.7.5 allows an infinite loop while parsing DTD content.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-16 14:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-32778",
                        "url": "https://ubuntu.com/security/CVE-2026-32778",
                        "cve_description": "libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-16 14:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-45186",
                        "url": "https://ubuntu.com/security/CVE-2026-45186",
                        "cve_description": "In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-10 07:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-41080",
                        "url": "https://ubuntu.com/security/CVE-2026-41080",
                        "cve_description": "libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-16 17:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56408",
                        "url": "https://ubuntu.com/security/CVE-2026-56408",
                        "cve_description": "libexpat before 2.8.2 has an integer overflow in copyString.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56403",
                        "url": "https://ubuntu.com/security/CVE-2026-56403",
                        "cve_description": "libexpat before 2.8.2 has an integer overflow in storeAtts.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-50219",
                        "url": "https://ubuntu.com/security/CVE-2026-50219",
                        "cve_description": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-04 06:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56412",
                        "url": "https://ubuntu.com/security/CVE-2026-56412",
                        "cve_description": "libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 17:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56404",
                        "url": "https://ubuntu.com/security/CVE-2026-56404",
                        "cve_description": "libexpat before 2.8.2 has an integer overflow in addBinding.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56405",
                        "url": "https://ubuntu.com/security/CVE-2026-56405",
                        "cve_description": "libexpat before 2.8.2 has an integer overflow in getAttributeId.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 16:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-32776",
                                "url": "https://ubuntu.com/security/CVE-2026-32776",
                                "cve_description": "libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-16 14:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-32777",
                                "url": "https://ubuntu.com/security/CVE-2026-32777",
                                "cve_description": "libexpat before 2.7.5 allows an infinite loop while parsing DTD content.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-16 14:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-32778",
                                "url": "https://ubuntu.com/security/CVE-2026-32778",
                                "cve_description": "libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-16 14:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-45186",
                                "url": "https://ubuntu.com/security/CVE-2026-45186",
                                "cve_description": "In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-10 07:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-41080",
                                "url": "https://ubuntu.com/security/CVE-2026-41080",
                                "cve_description": "libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-16 17:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56408",
                                "url": "https://ubuntu.com/security/CVE-2026-56408",
                                "cve_description": "libexpat before 2.8.2 has an integer overflow in copyString.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56403",
                                "url": "https://ubuntu.com/security/CVE-2026-56403",
                                "cve_description": "libexpat before 2.8.2 has an integer overflow in storeAtts.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-50219",
                                "url": "https://ubuntu.com/security/CVE-2026-50219",
                                "cve_description": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-04 06:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56412",
                                "url": "https://ubuntu.com/security/CVE-2026-56412",
                                "cve_description": "libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 17:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56404",
                                "url": "https://ubuntu.com/security/CVE-2026-56404",
                                "cve_description": "libexpat before 2.8.2 has an integer overflow in addBinding.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56405",
                                "url": "https://ubuntu.com/security/CVE-2026-56405",
                                "cve_description": "libexpat before 2.8.2 has an integer overflow in getAttributeId.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 16:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: NULL function-pointer dereference",
                            "    - debian/patches/CVE-2026-32776.patch: Fix NULL function-pointer dereference",
                            "      for empty external parameter entities in expat/lib/xmlparse.c,",
                            "      expat/tests/basic_tests.c.",
                            "    - CVE-2026-32776",
                            "  * SECURITY UPDATE: infinite loop while parsing DTD content",
                            "    - debian/patches/CVE-2026-32777-1.patch: lib: Reject XML_TOK_INSTANCE_START",
                            "      infinite loop in entityValueProcessor in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-32777-2.patch: misc_tests.c: Cover",
                            "      XML_TOK_INSTANCE_START infinite loop case in expat/tests/misc_tests.c.",
                            "    - CVE-2026-32777",
                            "  * SECURITY UPDATE: NULL pointer dereference",
                            "    - debian/patches/CVE-2026-32778-1.patch: copy prefix name to pool before",
                            "      lookup in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-32778-2.patch: test that we do not end up with a",
                            "      zombie PREFIX in the pool in expat/tests/nsalloc_tests.c.",
                            "    - CVE-2026-32778",
                            "  * SECURITY UPDATE: denial of service via moderately sized crafted XML input",
                            "    - debian/patches/CVE-2026-45186-1.patch: Make",
                            "      \"counting_start_element_handler\" count default attrs in",
                            "      expat/tests/basic_tests.c, expat/tests/handlers.c, expat/tests/handlers.h.",
                            "    - debian/patches/CVE-2026-45186-2.patch: test(attlist): Cover duplicate",
                            "      attribute names in expat/tests/basic_tests.c.",
                            "    - debian/patches/CVE-2026-45186-3.patch: tests: Define .attributes the first",
                            "      time around in expat/tests/basic_tests.c.",
                            "    - debian/patches/CVE-2026-45186-4.patch: tests: Make",
                            "      counting_start_element_handler enforce complete attribute lists in",
                            "      expat/tests/handlers.c.",
                            "    - debian/patches/CVE-2026-45186-5.patch: lib: Extract a constant for",
                            "      upcoming reuse in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-45186-6.patch: lib: Introduce",
                            "      ELEMENT_TYPE.defaultAttsNames in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-45186-7.patch: lib: Leverage",
                            "      ELEMENT_TYPE.defaultAttsNames for attribute collision detection in",
                            "      expat/lib/xmlparse.c.",
                            "    - CVE-2026-45186",
                            "  * SECURITY UPDATE: hash flooding caused by insufficient entropy",
                            "    - debian/patches/CVE-2026-41080-1.patch: lib: Inline function",
                            "      `get_hash_secret_salt` in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-41080-2.patch: lib: Drop unused parameter from",
                            "      function `generate_hash_secret_salt` in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-41080-3.patch: lib: Migrate hash salt storage to",
                            "      larger `struct sipkey` in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-41080-4.patch: lib: Drop unneeded `void *` casts",
                            "      in function `generate_hash_secret_salt` in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-41080-5.patch: lib: Extract 16 bytes of entropy",
                            "      (instead of 4 to 8) for hash flooding protection in expat/lib/internal.h,",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-41080-6.patch: lib: Introduce internal flag",
                            "      `m_hash_secret_salt_set` in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-41080-7.patch: lib: Introduce API function",
                            "      `XML_SetHashSalt16Bytes` in expat/lib/expat.h, expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-41080-8.patch: lib: Include `XML_SetHashSalt*`",
                            "      with entropy debugging in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-41080-9.patch: tests: Add basic coverage to",
                            "      `XML_SetHashSalt16Bytes` in expat/tests/basic_tests.c.",
                            "    - debian/patches/CVE-2026-41080-10.patch: doc: Document `XML_SetHashSalt` as",
                            "      being deprecated in expat/lib/expat.h, expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-41080-11.patch: cmake|windows: add missing export",
                            "      for new XML_SetHashSalt16Bytes in expat/lib/libexpat.def.cmake.",
                            "    - CVE-2026-41080",
                            "  * SECURITY UPDATE: integer overflow",
                            "    - debian/patches/CVE-2026-56408.patch: lib: Waterproof `copyString` from",
                            "      integer overflow in expat/lib/xmlparse.c.",
                            "    - CVE-2026-56408",
                            "  * SECURITY UPDATE: integer overflow",
                            "    - debian/patches/CVE-2026-56403-1.patch: lib: Protect function `storeAtts`",
                            "      from signed integer overflow in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-56403-2.patch: xmlwf: Protect function `xcsdup`",
                            "      from signed integer overflow in expat/xmlwf/xmlwf.c.",
                            "    - CVE-2026-56403",
                            "  * SECURITY UPDATE: use after free",
                            "    - debian/patches/CVE-2026-50219-1.patch: lib: Introduce handler call depth",
                            "      tracking in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-2.patch: lib: Prepare",
                            "      `m_notStandaloneHandler` calls for upcoming wrapping in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-3.patch: lib: Prepare",
                            "      `m_externalEntityRefHandler` calls for upcoming wrapping in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-4.patch: lib: Prepare",
                            "      `m_unknownEncodingHandler` calls for upcoming wrapping in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-5.patch: lib: Register",
                            "      `m_attlistDeclHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-6.patch: lib: Register",
                            "      `m_characterDataHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-7.patch: lib: Register `m_commentHandler`",
                            "      with handler call depth tracking in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-8.patch: lib: Register `m_defaultHandler`",
                            "      with handler call depth tracking in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-9.patch: lib: Register",
                            "      `m_elementDeclHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-10.patch: lib: Register",
                            "      `m_endCdataSectionHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-11.patch: lib: Register",
                            "      `m_endDoctypeDeclHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-12.patch: lib: Register",
                            "      `m_endElementHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-13.patch: lib: Register",
                            "      `m_endNamespaceDeclHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-14.patch: lib: Register",
                            "      `m_entityDeclHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-15.patch: lib: Register",
                            "      `m_externalEntityRefHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-16.patch: lib: Register",
                            "      `m_notationDeclHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-17.patch: lib: Register",
                            "      `m_notStandaloneHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-18.patch: lib: Register",
                            "      `m_processingInstructionHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-19.patch: lib: Register",
                            "      `m_skippedEntityHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-20.patch: lib: Register",
                            "      `m_startCdataSectionHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-21.patch: lib: Register",
                            "      `m_startDoctypeDeclHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-22.patch: lib: Register",
                            "      `m_startElementHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-23.patch: lib: Register",
                            "      `m_startNamespaceDeclHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-24.patch: lib: Register",
                            "      `m_unknownEncodingHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-25.patch: lib: Register",
                            "      `m_unparsedEntityDeclHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-26.patch: lib: Register `m_xmlDeclHandler`",
                            "      with handler call depth tracking in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-27.patch: lib: Protect `XML_GetBuffer` from",
                            "      being called from a handler in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-28.patch: lib: Protect `XML_Parse` from",
                            "      being called from a handler in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-29.patch: lib: Protect `XML_ParseBuffer`",
                            "      from being called from a handler in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-30.patch: lib: Protect `XML_ParserFree` from",
                            "      being called from a handler in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-31.patch: lib: Protect `XML_ParserReset`",
                            "      from being called from a handler in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-32.patch: tests: Cover calls forbidden from",
                            "      handlers in expat/tests/handlers.c, expat/tests/handlers.h,",
                            "      expat/tests/misc_tests.c.",
                            "    - CVE-2026-50219",
                            "  * SECURITY UPDATE: use after free (fix for CVE-2026-50219 was incomplete)",
                            "    - debian/patches/CVE-2026-56412.patch: lib: guard XML_TOK_DATA_CHARS handler",
                            "      calls in doCdataSection() in expat/lib/xmlparse.c.",
                            "    - CVE-2026-56412",
                            "  * SECURITY UPDATE: integer overflow",
                            "    - debian/patches/CVE-2026-56404.patch: lib: protect function addBinding from",
                            "      signed integer overflow in expat/lib/xmlparse.c.",
                            "    - CVE-2026-56404",
                            "  * SECURITY UPDATE: integer overflow",
                            "    - debian/patches/CVE-2026-56405.patch: lib: Protect function getAttributeId",
                            "      from signed integer overflow in expat/lib/xmlparse.c.",
                            "    - CVE-2026-56405",
                            ""
                        ],
                        "package": "expat",
                        "version": "2.7.4-1ubuntu0.1",
                        "urgency": "medium",
                        "distributions": "resolute-security",
                        "launchpad_bugs_fixed": [],
                        "author": "Isabel Garcia Contreras <isabel.garcia@canonical.com>",
                        "date": "Wed, 09 Sep 2026 10:49:36 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libxml2-16:riscv64",
                "from_version": {
                    "source_package_name": "libxml2",
                    "source_package_version": "2.15.2+dfsg-0.1ubuntu0.1",
                    "version": "2.15.2+dfsg-0.1ubuntu0.1"
                },
                "to_version": {
                    "source_package_name": "libxml2",
                    "source_package_version": "2.15.2+dfsg-0.1ubuntu0.2",
                    "version": "2.15.2+dfsg-0.1ubuntu0.2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-86140",
                        "url": "https://ubuntu.com/security/CVE-2026-86140",
                        "cve_description": "In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-09-05 05:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-74860",
                        "url": "https://ubuntu.com/security/CVE-2026-74860",
                        "cve_description": "A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-09-08 12:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-86140",
                                "url": "https://ubuntu.com/security/CVE-2026-86140",
                                "cve_description": "In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-09-05 05:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-74860",
                                "url": "https://ubuntu.com/security/CVE-2026-74860",
                                "cve_description": "A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-09-08 12:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: stack-based buffer overflow in xmlSnprintfElements",
                            "    - debian/patches/CVE-2026-86140.patch: fix: add bounds checks to",
                            "      xmlSnprintfElements in valid.c in valid.c.",
                            "    - CVE-2026-86140",
                            "  * SECURITY UPDATE: double free in Python SAX attributeDecl callback",
                            "    - debian/patches/CVE-2026-74860.patch: python: Do not decref string after",
                            "      adding to the list in python/libxml.c.",
                            "    - CVE-2026-74860",
                            ""
                        ],
                        "package": "libxml2",
                        "version": "2.15.2+dfsg-0.1ubuntu0.2",
                        "urgency": "medium",
                        "distributions": "resolute-security",
                        "launchpad_bugs_fixed": [],
                        "author": "John Breton <john.breton@canonical.com>",
                        "date": "Thu, 17 Sep 2026 08:09:57 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "rsyslog",
                "from_version": {
                    "source_package_name": "rsyslog",
                    "source_package_version": "8.2512.0-1ubuntu4.1",
                    "version": "8.2512.0-1ubuntu4.1"
                },
                "to_version": {
                    "source_package_name": "rsyslog",
                    "source_package_version": "8.2512.0-1ubuntu4.2",
                    "version": "8.2512.0-1ubuntu4.2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-78002",
                        "url": "https://ubuntu.com/security/CVE-2026-78002",
                        "cve_description": "A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted syslog messages. This vulnerability arises from an incorrect buffer size calculation during string replacement, causing memory corruption. Successful exploitation can lead to a denial of service (DoS) for the affected system.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-27 17:20:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-78002",
                                "url": "https://ubuntu.com/security/CVE-2026-78002",
                                "cve_description": "A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted syslog messages. This vulnerability arises from an incorrect buffer size calculation during string replacement, causing memory corruption. Successful exploitation can lead to a denial of service (DoS) for the affected system.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-27 17:20:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Denial of Service",
                            "    - debian/patches/CVE-2026-78002.patch: rainerscript: align replace sizing",
                            "      rewind in grammar/rainerscript.c.",
                            "    - CVE-2026-78002",
                            ""
                        ],
                        "package": "rsyslog",
                        "version": "8.2512.0-1ubuntu4.2",
                        "urgency": "medium",
                        "distributions": "resolute-security",
                        "launchpad_bugs_fixed": [],
                        "author": "John Breton <john.breton@canonical.com>",
                        "date": "Wed, 16 Sep 2026 12:41:35 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "rust-coreutils",
                "from_version": {
                    "source_package_name": "rust-coreutils",
                    "source_package_version": "0.8.0-0ubuntu3",
                    "version": "0.8.0-0ubuntu3"
                },
                "to_version": {
                    "source_package_name": "rust-coreutils",
                    "source_package_version": "0.10.0-1ubuntu2~26.04.1",
                    "version": "0.10.0-1ubuntu2~26.04.1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2166202,
                    2165041,
                    2163175,
                    2134860,
                    2159679,
                    2132368,
                    2137580,
                    2142900,
                    2150342,
                    2157011,
                    2157342,
                    2116290,
                    2158691,
                    2160614,
                    2153168,
                    2154338,
                    2154042,
                    2152801,
                    2146819,
                    2146818,
                    2155763,
                    2115782
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Backport 0.10.0-1ubuntu2 to Resolute (LP: #2166202)",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.10.0-1ubuntu2~26.04.1",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2166202
                        ],
                        "author": "Simon Johnsson <simon.johnsson@canonical.com>",
                        "date": "Thu, 03 Sep 2026 10:01:50 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/cp-fix-symlink-target-permissions.patch: Fix an issue where cp",
                            "    would alter the permissions of the source file, such as stripping the",
                            "    setuid bit (LP: #2165041)",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.10.0-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2165041
                        ],
                        "author": "Simon Johnsson <simon.johnsson@canonical.com>",
                        "date": "Wed, 26 Aug 2026 16:29:49 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Simon Johnsson ]",
                            "  * Merge with Debian unstable. Remaining changes: (LP: #2163175)",
                            "    - Install libstdbuf.so: Modify d/rules to export LIBSTDBUF_DIR as to not",
                            "      skip stdbuf, fix libstdbuf.so permissions, and install it in",
                            "      rust-coreutils.install.",
                            "    - Install hardlinks: Rename rust-coreutils.links to",
                            "      rust-coreutils.hardlinks.",
                            "    - Enable feat_systemd_logind: This allows commands such as who and pinky",
                            "      to work correctly. Introduces libsystemd-dev as a dependency.",
                            "    - Remove Build-Depends on lld: Debian added it as the preferred linker,",
                            "      but some partial architectures like i386 may be missing it.",
                            "    - d/rules: Fix vendored sources field creation. Debian does not have",
                            "      access to dh-cargo-vendored-sources so it uses a script instead.",
                            "      Change it to use dh-cargo-vendored-sources on Ubuntu instead.",
                            "    - d/rules: Skip failing tests.",
                            "    - Add patches:",
                            "      + build-stty",
                            "      + dd-ensure-full-writes",
                            "      + require-utility-to-be-invoked-at-matching-path",
                            "      + Tweak-release-build-profile",
                            "      + rust-vendor/glibc-2.42",
                            "      + rustix-use-libc-backend",
                            "    - Remove upstream patches:",
                            "      + fix-ppc64el-baudrate.diff: Launchpad's builders instead fails on",
                            "        ppc64le for this patch, the original source code is correct.",
                            "    - Update vendored rust crates",
                            "    - debian/control: Update XS-Vendored-Sources-Rust field",
                            "  * Drop changes:",
                            "    - Remove patches fixed upstream:",
                            "      + cp-respect-composite-flag",
                            "      + fix-cp-parents",
                            "      + fix-incomplete-locale-bundles",
                            "      + fix-locale-path: Debian adopted this patch.",
                            "  * New changes:",
                            "    - debian/patches/remove-workspace-members.patch: Remove workspace member",
                            "      array to prevent dh-cargo bypassing workspace-exclude.patch. Otherwise",
                            "      vendored dependencies would still think that they're part of the",
                            "      workspace.",
                            "  * Fixes:",
                            "    - File ownership changes when a file is mv'ed by root to a different file",
                            "      system (LP: #2134860)",
                            "    - Failing to build images: mv resolv.conf.tmp",
                            "      /build/chroot/etc/resolv.conf mv: File exists (os error 17)",
                            "      (LP: #2159679)",
                            "    - unaligned plus in \"ls -l\" output (LP: #2132368)",
                            "    - git-buildpackage ftbfs on resolute-proposed due to rust coreutils",
                            "      (LP: #2137580)",
                            "    - env: signal flags do not understand RTMIN+n notation (LP: #2142900)",
                            "    - date: width prefix in %N format specifier is ignored",
                            "      ( %3N, %6N always output full 9 nanosecond digits) (LP: #2150342)",
                            "    - changes in behaviour of cp in coreutils-from-uutils break test case in",
                            "      util-linux (LP: #2157011)",
                            "    - systemd: TEST-45-TIMEDATE is flaky with rust coreutils (LP: #2157342)",
                            "",
                            "  [ Varun Varma ]",
                            "  * debian/patches/df-statfs-fallback.patch: Add a fallback to statfs if the",
                            "    mount path could not be found normally (LP: #2116290).",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.10.0-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163175,
                            2134860,
                            2159679,
                            2132368,
                            2137580,
                            2142900,
                            2150342,
                            2157011,
                            2157342,
                            2116290
                        ],
                        "author": "Simon Johnsson <simon.johnsson@canonical.com>",
                        "date": "Tue, 11 Aug 2026 18:06:43 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            "  * Rework the source package to match the layout used by Ubuntu, so that",
                            "    merging Debian into Ubuntu no longer means undoing our repack:",
                            "    - Drop debian/repack.sh: the orig tarball is now the pristine GitHub tag.",
                            "    - d/watch: new, fetching the upstream tag plus the translations from",
                            "      uutils/coreutils-l10n as an l10n component tarball (unpacked in l10n/).",
                            "      Written in the version=4 syntax because devscripts in Debian does not",
                            "      support the newer \"Version: 5\" templates yet.",
                            "    - The vendored crates move out of the orig tarball into",
                            "      debian/rust-vendor/, generated by the new \"debian/rules vendor\" target",
                            "      with cargo-vendor-filterer (tier 2, *-*-linux-gnu* only). Vendor-only",
                            "      patches now have their own quilt series, debian/patches/rust-vendor/,",
                            "      applied by dh_quilt_patch; Build-Depends on quilt accordingly.",
                            "    - d/control: add the XS-Vendored-Sources-Rust field.",
                            "    - d/README.source: document the whole workflow.",
                            "  * debian/patches:",
                            "    - Drop use-vendor.diff, handled by \"cargo prepare-debian\" now.",
                            "    - Drop disable-utmp-classic.diff: utmp-classic is an OpenBSD-only target",
                            "      dependency, so it is never built on Linux; only its (unused) vendored",
                            "      copy remains. Ubuntu dropped the patch for the same reason.",
                            "    - Replace fix-locale-path.diff by Ubuntu's fix-locale-path.patch and add",
                            "      their use-l10n-translations-in-makefile.patch, the translations being",
                            "      installed from l10n/ instead of src/uu/*/locales/.",
                            "    - New workspace-exclude.patch, to keep debian/rust-vendor out of the",
                            "      cargo workspace.",
                            "    - Rebase the remaining patches on 0.10.0 and refresh the whole series",
                            "      with standard -p1 headers.",
                            "  * Ship debian/tldr.zip (English pages only): the pristine tarball does not",
                            "    carry the tldr archive that improve-man.diff turns into the EXAMPLES",
                            "    section of the manpages, and the build has no network access.",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.10.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Thu, 06 Aug 2026 00:20:00 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Use the debian/changelog date (via SOURCE_DATE_EPOCH) for the",
                            "    generated manpage date instead of the current build date, so the",
                            "    package builds reproducibly. New patch reproducible-man-date.diff.",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.9.0-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Thu, 04 Jun 2026 11:12:51 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Simon Johnsson ]",
                            "  * Remove lld as dependency as it is not available on i386:",
                            "    - d/control: Remove Build-Depends lld",
                            "    - d/rules: Change RUSTFLAGS to omit lld",
                            "  * debian/patches:",
                            "    - cp-respect-composite-flag: Cherry-pick fix from upstream for issue",
                            "      where the -a flag is not considered recursive due to flag stripping",
                            "      (LP: #2158691)",
                            "",
                            "  [ Varun Varma ]",
                            "  * debian/patches:",
                            "    - rustix-use-libc-backend: Switch rustix backend to libc to solve",
                            "      the error where tools that rely on LD_PRELOAD have altered",
                            "      behaviour with the default rustix backend (LP: #2160614).",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.9.0-2ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2158691,
                            2160614
                        ],
                        "author": "Simon Johnsson <simon.johnsson@canonical.com>",
                        "date": "Tue, 14 Jul 2026 17:15:36 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable. Remaining changes: (LP: #2153168)",
                            "    - Install libstdbuf.so",
                            "    - Install hardlinks",
                            "    - Refresh upstream patches",
                            "    - Use direct GitHub tarball instead of debian/repack.sh",
                            "    - d/rules:",
                            "      + Add vendoring targets",
                            "      + Build verbosely",
                            "      + Skip failing tests",
                            "    - d/watch: add watch file",
                            "    - d/patches:",
                            "      + Tweak-release-build-profile.patch",
                            "      + workspace-exclude.patch",
                            "      + build-stty.patch",
                            "      + require-utility-to-be-invoked-at-matching-path.patch",
                            "      + glibc-2.42.patch",
                            "      + dd-ensure-full-writes.patch",
                            "      + use-l10n-translations-in-makefile.patch",
                            "      + fix-locale-path.patch",
                            "      + fix-incomplete-locale-bundles.patch",
                            "    - d/control: update XS-Vendored-Sources-Rust field",
                            "    - vendor: update vendored deps",
                            "    - l10n/: update translations",
                            "  * Fixes:",
                            "    - xattrs break ls formatting (LP: #2154338)",
                            "    - ls: files are not sorted in alphabetical order when using",
                            "      --group-directories-first or if LC_ALL is unset (LP: #2154042)",
                            "  * Drop changes:",
                            "    - d/p/tee-fix-input-with-sleep.patch: The underlying issue was fixed",
                            "      upstream, so drop the patch.",
                            "  * New changes:",
                            "    - Enable feat_systemd_logind to fix who not showing output",
                            "      (LP: #2152801, LP: #2146819, LP: #2146818)",
                            "      + d/control: Add libsystemd-dev as a dependency.",
                            "      + d/rules: Link systemd and add feat_systemd_logind to CARGOFLAGS.",
                            "    - d/p/fix-cp-parents.patch: Cherry-pick fix from upstream for cp --parents",
                            "      bug resulting in build failures (LP: #2155763)",
                            "    - Remove unnecessary upstream patches:",
                            "      + disable-utmp-classic.diff",
                            "      + fix-locale-path.diff: Locale handling is different on Ubuntu, using",
                            "        l10n (see the new fix-locale-path.patch).",
                            "      + fix-man.diff: Uncommented in the upstream series.",
                            "      + fix-ppc64el-baudrate.diff: Launchpad's builders instead fails on",
                            "        ppc64le for this patch, the original source code is correct.",
                            "      + use-vendor.diff: Vendor handling is different on Ubuntu.",
                            "    - Remove docs/tldr.zip from Debian upstream",
                            "    - Delete locales shipped in Debian upstream under src/",
                            "    - Move vendored dependencies to debian/",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.9.0-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153168,
                            2154338,
                            2154042,
                            2152801,
                            2146819,
                            2146818,
                            2155763
                        ],
                        "author": "Simon Johnsson <simon.johnsson@canonical.com>",
                        "date": "Thu, 04 Jun 2026 15:54:29 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Fix the i386 (32-bit) FTBFS (OOM): the test build did fat LTO +",
                            "    codegen-units=1 + full debuginfo on the giant all-utils crate and ran out",
                            "    of the ~3GB address space. Set CARGO_PROFILE_RELEASE_LTO=thin,",
                            "    CODEGEN_UNITS=16 and DEBUG=1 via env on all 32-bit arches so every cargo",
                            "    invocation honours them, replacing the sed hacks that missed the test step.",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.9.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Sun, 31 May 2026 10:04:41 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.9.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Sat, 30 May 2026 17:07:32 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Fix the s390x FTBFS (150min buildd inactivity timeout). The previous",
                            "    sed only disabled LTO around dh_auto_install, so the default build and",
                            "    the test build still did fat LTO + codegen-units=1 + full debuginfo on",
                            "    the giant all-utils crate, which is what actually timed out. Now set",
                            "    CARGO_PROFILE_RELEASE_LTO=false, CODEGEN_UNITS=16 and DEBUG=1 via env so",
                            "    every cargo invocation honours them.",
                            "  * Skip the (non-gating) test suite on s390x: the release test build was",
                            "    the step hitting the timeout (killed at \"Compiling unindent\").",
                            "  * Use lld as the linker on every architecture when it is available, not",
                            "    just on s390x: ld.lld is detected at build time (via command -v) and",
                            "    -fuse-ld=lld is added when present, falling back to the default linker",
                            "    otherwise. lld links the multicall binary much faster than GNU ld.",
                            "    Build-Depend on lld on all architectures (it ships from the same",
                            "    llvm-toolchain source as the already-required libclang-dev).",
                            "  * Log the linker on every architecture: emit the -Wl,-v banner on every",
                            "    link and print rustc -vV / ld.lld / ld at configure time, so every build",
                            "    log records which linker ran. Previously the ld.lld check lived in",
                            "    dh_auto_install (never reached when the build timed out) and only on s390x.",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.8.0-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Thu, 28 May 2026 08:08:46 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Disable LTO on s390x: thin LTO + lld in 0.8.0-4 still timed out on",
                            "    the buildd, so turn LTO off entirely on s390x.",
                            "  * Print ld.lld version and ask the linker to log itself (-Wl,-v) so",
                            "    the build log shows which linker was actually invoked.",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.8.0-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Wed, 27 May 2026 23:11:39 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Use lld as the linker on s390x: thin LTO alone in 0.8.0-3 did not",
                            "    unblock the buildd timeout, so switch the final link to ld.lld.",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.8.0-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Wed, 27 May 2026 08:04:14 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Use thin LTO on s390x to avoid linker timeouts on the buildd",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.8.0-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Wed, 27 May 2026 08:04:14 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * try to unbreak the ppc64 build",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.8.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Sun, 17 May 2026 14:58:46 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release (Closes: #1134876)",
                            "  * Improve the manpage (LP: #2115782)",
                            "  * Add manpage symlink for coreutils binary (no-manual-page)",
                            "  * Extend disable-utmp-classic.diff to cover the new",
                            "    [target.'cfg(target_os = \"openbsd\")'.dependencies] block in",
                            "    src/uucore/Cargo.toml introduced upstream in 0.8.0 (fixes FTBFS).",
                            "  * Disable fix-man.diff: it converts .ftl bullet markers from `-` to `*`",
                            "    and rewrites top-level `key = value` lines as markdown bullets, which",
                            "    is invalid Fluent syntax. uudoc loads each utility's locale via",
                            "    setup_localization_or_exit and was aborting manpage generation with",
                            "    a Localization parse error. Patch kept in debian/patches/ but",
                            "    commented out in series until it can be rewritten Fluent-cleanly.",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.8.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2115782
                        ],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Wed, 06 May 2026 13:08:52 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "  * Move to https://salsa.debian.org/rust-team/coreutils",
                            "  * Improve the manpages example display",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.7.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Mon, 09 Mar 2026 06:59:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "  * Vendor dependencies. Too hard to maintain in Debian",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.6.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Tue, 17 Feb 2026 13:48:51 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "",
                            "  [ Jeremy Bícha]",
                            "  * remove unused Build-Depends: librust-unix-socket-dev",
                            "",
                            "  [ Peter Michael Green ]",
                            "  * Add patch for nix 0.30",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.0.30-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Peter Michael Green <plugwash@debian.org>",
                        "date": "Tue, 30 Sep 2025 12:45:34 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Bump the notify dependency to v8",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.0.30-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "NoisyCoil <noisycoil@debian.org>",
                        "date": "Wed, 24 Sep 2025 19:38:04 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Also ship with b3sum (Closes: #1107092)",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.0.30-3~exp1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Mon, 02 Jun 2025 20:43:15 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            }
        ],
        "snap": []
    },
    "added": {
        "deb": [],
        "snap": []
    },
    "removed": {
        "deb": [],
        "snap": []
    },
    "notes": "Changelog diff for Ubuntu 26.04 resolute image from daily image serial 20260918 to 20260921",
    "from_series": "resolute",
    "to_series": "resolute",
    "from_serial": "20260918",
    "to_serial": "20260921",
    "from_manifest_filename": "daily_manifest.previous",
    "to_manifest_filename": "manifest.current"
}