Skip to content

Followup to "better no-dsa support in PTS" on "low severity" entries

Filling a new issue: As @jmm has highlighted in freexian-team/project-funding#4 (comment 230200)

Salvatore noticed that the "low severity" entry is currently also displayed for suites within LTS (e.g. https://tracker.debian.org/pkg/lighttpd). This should only be displayed for stable and oldstable while under regular security maintenance:

  • The meaning of the tags is different for non-LTS (as there are not point releases)
  • The upcoming landing page will confuse people as it's specifically focused on point releases
  • There's no general expectation that maintainers contribute to LTS, so this might confuse or annoy people

A machine-readable list of suites which are supported under the security team's responsibility can be fetched via https://security-tracker.debian.org/tracker/distributions.json

freexian-team/project-funding#4 (comment 230271) contains how the listing could look like.

Edited by Salvatore Bonaccorso