
Like each month, have a look at the work funded by Freexian’s Debian LTS offering.
Debian LTS contributors
In May, 22 contributors have been paid to work on Debian LTS, their reports are available:
- Abhijith PA did 8.0h (out of 0.0h assigned and 8.0h from previous period).
- Adrian Bunk did 26.0h (out of 26.0h assigned).
- Andreas Henriksson did 1.0h (out of 15.0h assigned and 3.0h from previous period), thus carrying over 17.0h to the next month.
- Andrej Shadura did 3.0h (out of 10.0h assigned), thus carrying over 7.0h to the next month.
- Bastien Roucariès did 20.0h (out of 20.0h assigned).
- Ben Hutchings did 8.0h (out of 20.0h assigned and 4.0h from previous period), thus carrying over 16.0h to the next month.
- Carlos Henrique Lima Melara did 12.0h (out of 11.0h assigned and 1.0h from previous period).
- Chris Lamb did 15.5h (out of 0.0h assigned and 15.5h from previous period).
- Daniel Leidert did 25.0h (out of 26.0h assigned), thus carrying over 1.0h to the next month.
- Emilio Pozuelo Monfort did 21.0h (out of 16.75h assigned and 11.0h from previous period), thus carrying over 6.75h to the next month.
- Guilhem Moulin did 11.5h (out of 8.5h assigned and 6.5h from previous period), thus carrying over 3.5h to the next month.
- Jochen Sprickerhof did 3.5h (out of 8.75h assigned and 17.5h from previous period), thus carrying over 22.75h to the next month.
- Lee Garrett did 26.0h (out of 12.75h assigned and 13.25h from previous period).
- Lucas Kanashiro did 20.0h (out of 18.0h assigned and 2.0h from previous period).
- Markus Koschany did 20.0h (out of 26.25h assigned), thus carrying over 6.25h to the next month.
- Roberto C. Sánchez did 20.75h (out of 24.0h assigned), thus carrying over 3.25h to the next month.
- Santiago Ruano Rincón did 15.0h (out of 12.5h assigned and 2.5h from previous period).
- Sean Whitton did 6.25h (out of 6.0h assigned and 2.0h from previous period), thus carrying over 1.75h to the next month.
- Sylvain Beucler did 26.25h (out of 26.25h assigned).
- Thorsten Alteholz did 15.0h (out of 15.0h assigned).
- Tobias Frost did 12.0h (out of 12.0h assigned).
- Utkarsh Gupta did 1.0h (out of 15.0h assigned), thus carrying over 14.0h to the next month.
Evolution of the situation
In May, we released 54 DLAs.
The LTS Team was particularly active in May, publishing a higher than normal number of advisories, as well as helping with a wide range of updates to packages in stable and unstable, plus some other interesting work. We are also pleased to welcome several updates from contributors outside the regular team.
- Notable security updates:
- containerd, prepared by Andreas Henriksson, fixes a vulnerability that could cause containers launched as non-root users to be run as root
- libapache2-mod-auth-openidc, prepared by Moritz Schlarb, fixes a vulnerability which could allow an attacker to crash an Apache web server with libapache2-mod-auth-openidc installed
- request-tracker4, prepared by Andrew Ruthven, fixes multiple vulnerabilities which could result in information disclosure, cross-site scripting and use of weak encryption for S/MIME emails
- postgresql-13, prepared by Bastien Roucariès, fixes an application crash vulnerability that could affect the server or applications using libpq
- dropbear, prepared by Guilhem Moulin, fixes a vulnerability which could potentially result in execution of arbitrary shell commands
- openjdk-17, openjdk-11, prepared by Thorsten Glaser, fixes several vulnerabilities, which include denial of service, information disclosure or bypass of sandbox restrictions
- glibc, prepared by Sean Whitton, fixes a privilege escalation vulnerability
- Notable non-security updates:
- wireless-regdb, prepared by Ben Hutchings, updates information reflecting changes to radio regulations in many countries
This month’s contributions from outside the regular team include the libapache2-mod-auth-openidc update mentioned above, prepared by Moritz Schlarb (the maintainer of the package); the update of request-tracker4, prepared by Andrew Ruthven (the maintainer of the package); and the updates of openjdk-17 and openjdk-11, also noted above, prepared by Thorsten Glaser.
Additionally, LTS Team members contributed stable updates of the following packages:
- rubygems and yelp/yelp-xsl, prepared by Lucas Kanashiro
- simplesamlphp, prepared by Tobias Frost
- libbson-xs-perl, prepared by Roberto C. Sánchez
- fossil, prepared by Sylvain Beucler
- setuptools and mydumper, prepared by Lee Garrett
- redis and webpy, prepared by Adrian Bunk
- xrdp, prepared by Abhijith PA
- tcpdf, prepared by Santiago Ruano Rincón
- kmail-account-wizard, prepared by Thorsten Alteholz
Other contributions were also made by LTS Team members to packages in unstable:
- proftpd-dfsg DEP-8 tests (autopkgtests) were provided to the maintainer, prepared by Lucas Kanashiro
- a regular upload of libsoup2.4, prepared by Sean Whitton
- a regular upload of setuptools, prepared by Lee Garrett
Freexian, the entity behind the management of the Debian LTS project, has been working for some time now on the development of an advanced CI platform for Debian-based distributions, called Debusine. Recently, Debusine has reached a level of feature implementation that makes it very usable. Some members of the LTS Team have been using Debusine informally, and during May LTS coordinator Santiago Ruano Rincón has made a call for the team to help with testing of Debusine, and to help evaluate its suitability for the LTS Team to eventually begin using as the primary mechanism for uploading packages into Debian. Team members who have started using Debusine are providing valuable feedback to the Debusine development team, thus helping to improve the platform for all users. Actually, a number of updates, for both bullseye and bookworm, made during the month of May were handled using Debusine, e.g. rubygems’s DLA-4163-1.
By the way, if you are a Debian Developer, you can easily test Debusine following the instructions found at https://wiki.debian.org/DebusineDebianNet.
DebConf, the annual Debian Conference, is coming up in July and, as is customary each year, the week preceding the conference will feature an event called DebCamp. The DebCamp week provides an opportunity for teams and other interested groups/individuals to meet together in person in the same venue as the conference itself, with the purpose of doing focused work, often called “sprints”. LTS coordinator Roberto C. Sánchez has announced that the LTS Team is planning to hold a sprint primarily focused on the Debian security tracker and the associated tooling used by the LTS Team and the Debian Security Team.
Thanks to our sponsors
Sponsors that joined recently are in bold.
- Platinum sponsors:
- Toshiba Corporation (for 116 months)
- Civil Infrastructure Platform (CIP) (for 84 months)
- VyOS Inc (for 48 months)
- Gold sponsors:
- Roche Diagnostics International AG (for 126 months)
- Akamai - Linode (for 120 months)
- Babiel GmbH (for 110 months)
- Plat’Home (for 109 months)
- University of Oxford (for 66 months)
- Deveryware (for 53 months)
- EDF SA (for 38 months)
- Dataport AöR (for 13 months)
- CERN (for 11 months)
- Silver sponsors:
- Domeneshop AS (for 131 months)
- Nantes Métropole (for 125 months)
- Univention GmbH (for 117 months)
- Université Jean Monnet de St Etienne (for 117 months)
- Ribbon Communications, Inc. (for 111 months)
- Exonet B.V. (for 100 months)
- Leibniz Rechenzentrum (for 95 months)
- Ministère de l’Europe et des Affaires Étrangères (for 78 months)
- Cloudways by DigitalOcean (for 68 months)
- Dinahosting SL (for 66 months)
- Bauer Xcel Media Deutschland KG (for 60 months)
- Platform.sh SAS (for 60 months)
- Moxa Inc. (for 54 months)
- sipgate GmbH (for 52 months)
- OVH US LLC (for 50 months)
- Tilburg University (for 50 months)
- GSI Helmholtzzentrum für Schwerionenforschung GmbH (for 41 months)
- THINline s.r.o. (for 14 months)
- Copenhagen Airports A/S (for 8 months)
- Bronze sponsors:
- Evolix (for 131 months)
- Seznam.cz, a.s. (for 131 months)
- Intevation GmbH (for 128 months)
- Linuxhotel GmbH (for 128 months)
- Daevel SARL (for 127 months)
- Bitfolk LTD (for 126 months)
- Megaspace Internet Services GmbH (for 126 months)
- Greenbone AG (for 125 months)
- NUMLOG (for 125 months)
- WinGo AG (for 124 months)
- Entr’ouvert (for 115 months)
- Adfinis AG (for 113 months)
- Tesorion (for 108 months)
- Laboratoire LEGI - UMR 5519 / CNRS (for 107 months)
- Bearstech (for 99 months)
- LiHAS (for 99 months)
- Catalyst IT Ltd (for 94 months)
- Demarcq SAS (for 88 months)
- Université Grenoble Alpes (for 74 months)
- TouchWeb SAS (for 66 months)
- SPiN AG (for 63 months)
- CoreFiling (for 59 months)
- Institut des sciences cognitives Marc Jeannerod (for 54 months)
- Observatoire des Sciences de l’Univers de Grenoble (for 50 months)
- Tem Innovations GmbH (for 45 months)
- WordFinder.pro (for 44 months)
- CNRS DT INSU Résif (for 43 months)
- Soliton Systems K.K. (for 38 months)
- Alter Way (for 36 months)
- Institut Camille Jordan (for 26 months)
- SOBIS Software GmbH (for 11 months)
- Tuxera Inc.