[Pkg-salt-team] Salt status in Debian.

Thomas Martin tmartincpp at gmail.com
Wed Oct 12 10:02:04 BST 2022


Hi Team,

I'm currently working on a project to orchestrate workstations and I
think that SaltStack is the most relevant solution for me.

But I'm having concerns about the lack of security updates of Salt in
Debian Stable and oldstable, support seems discontinued.
For example this CVE is still affecting Debian's versions :
https://security-tracker.debian.org/tracker/CVE-2022-22934

Due to the nature of Salt, security seems *very* important so I'm a
bit confused about the lack of Salt's updates in Stable and OldStable.
Should I contact the security team ?

Would you advise to go for another solution packaged by Debian (like
Puppet or Chef) or to use the official Salt repository
(https://repo.saltproject.io/#debian) ?

Let me know if I can help.

Regards,
Thomas



More information about the pkg-salt-team mailing list