SECURITY UPDATE: unexpected SSH agent authentication during public-key SSH-
based transfers
debian/patches/CVE-2025-15224.patch: Require private key or SSH agent for
public-key authentication; prevent attempted public-key auth when neither
private key nor agent present; fix missing check that allowed public-key
auth flag without key or agent.