Re: Bug#1142947: Please include Static-Built-Using information in the security tracker

Alexander Kjäll <[email protected]> Tue, 28 Jul 2026 17:20:29 +0200
Newsgroups gmane.linux.debian.rust,gmane.linux.debian.alioth.pkg-go-maintainers,gmane.comp.lang.haskell.debian,gmane.linux.debian.devel.ocaml
Message-ID <CAOuTi9VWLq4kc73oh19d=JGakbbeHzGfeVgNo8hr73dhgqqCcg@mail.gmail.com>
Hi

I think this can be important for more languages that are statically
linked in Debian.

I'll cc the Zig, Haskell and OCalm teams also.

//Alex

Den tis 28 juli 2026 kl 16:17 skrev Nilesh Patra <[email protected]>:
>
> Package: security-tracker
> Severity: wishlist
> Tags: security
> X-Debbugs-Cc: [email protected]
>
> Hi,
>
> I happened to notice https://rustsec.debian.net/ recently, and that relies
> on "Static-Built-Using" to track which disclosed vulnerability impacts
> what package.
>
> Given that Go world is also statically linked, such a tracker may also make
> sense for Golang.
>
> Thorsten gave the suggestion on mailing list (mail below) to have security
> tracker support it. I agree that it'd be great to have it at a central place.
>
> On 27/07/26 10:22 pm, Thorsten Alteholz wrote:
> > Hi everybody,
> >
> > On 27.07.26 17:43, Nilesh Patra wrote:
> >> Given that Go world is also statically linked, does such a tracker makes
> >> sense for the Go team as well?
> >
> > I like the idea to show these information.
> > I don't like the idea of having another website to look for security
> > information.
> >  From my point of view this should be part of the official security tracker.
> >
> >    Thorsten
> >
>