Re: Security update for Neutron (CVE-2026-55707 aka #1143170, OSSN-0102 aka #1142937)

Aurelien Jarno <[email protected]>
Newsgroups gmane.linux.debian.devel.wb-team,gmane.linux.debian.devel.release
Message-ID <[email protected]>
Hi,

On 2026-08-18 17:21, Philipp Kern wrote:
> AIUI here it's only needed as a build dependency and not as an actual
> runtime dependency, right? So the workaround is fair and there are only very
> few things in -updates that all get looked at by SRM. For runtime
> dependencies I'd feel stronger about a judgement call of importing the
> package into -security instead.

I think it depends what goes into -stable, it's not impossible that a 
package in -security built against something into -stable gets a strict 
runtime dependency on that version. But that should be very rare.

Regards
Aurelien
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.