Re: Security update for Neutron (CVE-2026-55707 aka #1143170, OSSN-0102 aka #1142937)
Aurelien Jarno <[email protected]>
| Newsgroups | gmane.linux.debian.devel.wb-team,gmane.linux.debian.devel.release |
|---|---|
| Message-ID | <[email protected]> |
Hi, On 2026-08-18 17:21, Philipp Kern wrote: > AIUI here it's only needed as a build dependency and not as an actual > runtime dependency, right? So the workaround is fair and there are only very > few things in -updates that all get looked at by SRM. For runtime > dependencies I'd feel stronger about a judgement call of importing the > package into -security instead. I think it depends what goes into -stable, it's not impossible that a package in -security built against something into -stable gets a strict runtime dependency on that version. But that should be very rare. Regards Aurelien