mercurial (5.6.1-4+deb11u1) bullseye-security; urgency=medium
* Non-maintainer upload by the Debian LTS Security Team.
[ Andreas Henriksson ]
* Cherry-pick and massage bookworm (stable) patches by jcristau to apply
on bullseye version of the package.
[ Julien Cristau ]
* CVE-2025-2361: reflected XSS in hgweb (closes: #
1100899)
* patchbomb: don't test ambiguous address
(fixes FTBFS after python's fix for CVE-2023-27043).
[dgit import unpatched mercurial 5.6.1-4+deb11u1]