[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: bouncycastle: proposed bullseye LTS fix for CVE-2026-5588



Hello James,

On 24/04/2026 01:27, James Montgomery wrote:
One thing I'd like to check while I'm finding my footing: is contributing
supporting research to TODO entries in data/CVE/list still considered
worthwhile? My understanding is that adding NOTE: lines with upstream commit
references, CVSSv3 context, or "not-affected" rationale to existing TODO
stanzas helps whoever picks the CVE up next and can avoid duplicate research —
all without requiring any upload privileges. Is that a contribution the team
finds useful, or would you rather the tracker triage be left to established
contributors as well?

Initial triage is performed by the Security Team; the LTS Team usually does a second pass specifically for bullseye.

I believe TODO entries are meant for the Security Team to track their own work. Maybe ask around on #debian-security to check if this is welcome contribution -- I can't tell for them :)

Cheers!
Sylvain Beucler
Debian LTS Team


Reply to: