Debian Long Term Support work 2024 July

LTS

  • Internal tooling updates related to the monthly report. Finalized some started tasks from last month.
    • ensure accuracy of data included in the monthly LTS report
    • overall clean-up and refactor
  • Compiled a report on the packages that should be added back to dla-needed. Sent an email with my conclusions.

ELTS

  • Prepared a commit to mark a lot of packages as EOL for buster considering the switch. After approval from front-desk I commited it so now 694 CVEs are marked with end-of-life. Sometimes it really pays off to write automated scripts that can do the work for you.
  • openssh: Marked CVE-2024-6387 as not affected for buster.
  • varnish
    • Marked CVE-2024-30156  as ignored for buster.
    • Looking into why some tests are failing with the proposed correction for CVE-2023-44487. Realized that it may or may not fail legitimately. May continue later.