[Git][security-tracker-team/security-tracker][master] Remove a few packages from dla-needed

Bastien Roucariès (@rouca) rouca at debian.org
Wed Aug 5 18:52:26 BST 2026



Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d9060f41 by Bastien Roucariès at 2026-08-05T19:52:05+02:00
Remove a few packages from dla-needed

- - - - -


1 changed file:

- data/dla-needed.txt


Changes:

=====================================
data/dla-needed.txt
=====================================
@@ -58,9 +58,6 @@ aom/bookworm
   NOTE: 20260709: AV1 *encoder* flaws (SVC layer-id/LAP), CVE-2026-56208..56211; only
   NOTE: 20260709: bookworm (3.6.0) affected, bullseye not-affected (code added in aom 2.0.0).
 --
-apache-directory-api
-  NOTE: 20260608: Added by Front-Desk (rouca)
---
 apache-log4j2/bullseye
   NOTE: 20260413: Added by Front-Desk (rouca)
 --
@@ -85,9 +82,6 @@ busybox
   NOTE: 20260722: Also add for bookworm; CVE-2026-38752..38755 (ash/awk)
   NOTE: 20260722: share code, sponsored, already queued bullseye+ELTS (utkarsh)
 --
-c3p0/bullseye
-  NOTE: 20260414: Added by Front-Desk (rouca)
---
 ca-certificates (rouca)
   NOTE: 20250613: Added by Front-Desk (rouca)
   NOTE: 20250613: Lack some certificates #1095913 (rouca/FD)
@@ -116,10 +110,6 @@ calibre (Abhijith)
 cjson
   NOTE: 20260801: Added by Front-Desk (ta)
 --
-ckeditor/bullseye
-  NOTE: 20241002: Added by Front-Desk (Beuc)
-  NOTE: 20241002: Multiple CVEs have been piling up (Beuc/front-desk)
---
 clamav (Emilio)
   NOTE: 20260711: Added by Front-Desk (utkarsh)
   NOTE: 20260711: Needs a newer rustc to be backported as well. (utkarsh)
@@ -145,12 +135,6 @@ cyrus-imapd
   NOTE: 20260717: Added by Front-Desk (Beuc)
   NOTE: 20260717: Upcoming DSA (Beuc/front-desk)
 --
-docker-registry
-  NOTE: 20260419: Added by Front-Desk (rouca)
-  NOTE: 20260725: Also add for bookworm (2.8.2); CVE-2026-33540 proxyauth.go
-  NOTE: 20260725: realm handling identical to bullseye. CVE-2026-41888 is
-  NOTE: 20260725: not-affected there (tag-delete code is 3.0.0+). (utkarsh/front-desk)
---
 docker.io
   NOTE: 20250805: Added by Front-Desk (rouca)
   NOTE: 20260714: Also add for bookworm (Beuc/front-desk)
@@ -242,16 +226,6 @@ glances/bullseye
   NOTE: 20260518: Added by Front-Desk (Beuc)
   NOTE: 20260518: Many postponed vulnerabilities piled-up (Beuc/front-desk)
 --
-golang-github-gorilla-csrf/bullseye
-  NOTE: 20250422: Added by Front-Desk (rouca)
-  NOTE: 20250422: Need to binNMU reverse depends (in that order): golang-github-alecthomas-chroma, golang-github-niklasfasching-go-org, golang-github-yuin-goldmark-highlighting, hugo (rouca)
-  NOTE: 20250621: Re-add as binNMUs are not all properly Installed in the archive, e.g.
-  NOTE: 20250621: https://buildd.debian.org/status/package.php?p=hugo&suite=bullseye-security
-  NOTE: 20250621: https://buildd.debian.org/status/package.php?p=golang-github-alecthomas-chroma&suite=bullseye-security
-  NOTE: 20250621: https://buildd.debian.org/status/package.php?p=golang-github-niklasfasching-go-org&suite=bullseye-security
-  NOTE: 20250621: still stuck at Uploaded phase, probably due to missing sources at security.debian.org (Beuc)
-  NOTE: 20251107: Please coordinate with FTP masters to unblock the situation (Beuc/front-desk)
---
 golang-glog/bullseye
   NOTE: 20250209: Added by Front-Desk (apo)
   NOTE: 20251107: Re-add as binNMUs are not all properly Installed in the archive:



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d9060f413ca4329f1965ea5f3bdddc99e67f3648

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d9060f413ca4329f1965ea5f3bdddc99e67f3648
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260805/5f5240ba/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list