During the month of September, I have worked on the following task for LTS and ELTS: - CSAF exporter: + Finished a working version of the tool - Included multiple improvements and optimizations (thanks to Helmut!) + Implemented the server_task for the CSAF exporter - Automation of the deploy of the server_task in Freexian's infrastructure - Validated the server_task is working as expected - Also tested the publication of the CSAF documents to a S3 bucket implemented by Helmut - VEX statements export: + Had interesting discussion with people from industry about some changellenges and how other companies are addressing them + Follow-up of the meeting with Santiago (more discussions) + We will implement VEX statements using the CSAF format - Agreed by the VEX working group at the moment + Plans for its implementation using the same codebase used for advisories - syslog-ng + Reviewed and tested syslog-ng security update for buster and stretch for Bastien - We should come up with a template for a email requesting review. TBD. - ClamAV + Backported version 1.0.9 to all [E]LTS releases + DLA-4292-1 and ELA-1511-1 - linux-6.1 + Backported version from LTS to ELTS releases (buster and stretch) + There was an issue with the code signing in the Debian infrastructure and this update was not published to LTS users + The update for ELTS is also on hold due to the above (the code signing is working well in Freexian's infrastructure) - Meetings + Attended the VEX group meeting + Attended the Freexian team bi-weekly meeting + Attended the monthly LTS/ELTS team meeting