During the month of May, I have worked on the following tasks for LTS and ELTS: - CSAF exporter + Wrote some integration tests to allow some refactoring + Started the refactoring to then add support for source packages. At the moment, it supports only binary packages, which makes harder to indicate that the source package is affected by a given CVE but not the generated binaries. - Freexian's security tracker + Continue to implement a verbose mode to allow users to pass an option and see what is changing under the hood. - Needs a MR to get a review. - linux updates for ELTS + linux-5.10: released ELA-1704-1 and ELA-1738-1 + linux-6.1: released ELA-1705-1 and ELA-1739-1 - erlang + erlang: released DLA-4590-1 + erlang: released ELA-1736-1 + Forwarded all changes to the maitainer's git repo. Everything is already merged. - Gitlab dependencies + Gitlab will be removed from unstable and therefore all its dependencies will become unnecessary in the archive. + Some of those dependencies has some security issues not easy to solve. I tried to identify dependencies, such as ruby-saml, with security problems to be called unsupported in bookworm LTS. + The biggest concern is ruby-rack, which is a key rails dependency. We still ship version 2.x which contains many vulnerabilities, and upstream recommends version 3.x to improve security. However, since this is an important package not for gitlab only, we will do our best to keep supporting it. - Meetings + Attended the Freexian team bi-weekly meeting. + Attended the monthly LTS/ELTS team meeting.