Hi, the recent uploads of golang-1.10 (version 1.10.6-1) and golang-1.11 (version 1.11.3-1) include the fixes for the CVEs assigned to those packages, namely: CVE-2018-16875 CVE-2018-16874 CVE-2018-16873 Unfortunately, those CVS numbers have not been included in d/changelog, so the automatic sync didn't happen. Could you please adjust the fixed versions in security-tracker.d.o? Thanks! https://security-tracker.debian.org/tracker/source-package/golang-1.10 https://security-tracker.debian.org/tracker/source-package/golang-1.11 Regards, Tobias
Attachment:
signature.asc
Description: OpenPGP digital signature