Hi, Ben Hutchings <b...@decadent.org.uk> (2019-02-10): > On Sun, 2019-02-10 at 14:42 +0100, Hilko Bengen wrote: > > Package: debian-installer > > Severity: normal > > > > Dear Maintainers, > > > > as of now the beep package is still going to be shipped with buster > > despite having CVE-worthy bugs with no maintainer activity in several > > months. The only apparent reason for this is that it is included by d-i > > on one specific armel[1] flavor -- I am not even sure if it would > > actually be needed (or even used) there. > > > > Please consider removing the package from the installer. Thank you. > > > > Cheers, > > -Hilko > > > > [1] > > debian-installer-20190118/build/pkg-lists/netboot/network-console/armel/ixp4xx.cfg > > This configuration is no longer used as we already dropped support for > this platform in stretch. Please go ahead with removal of beep.
Following up to a question on IRC, I've checked there were no other users of the beep command in the debian-boot@ maintained packages, with only network-console depending on the beep command, without depending on the relevant udeb (it was apparently relying on the pkg-lists mechanism to get the udeb installed…). Given those: https://salsa.debian.org/installer-team/debian-installer/commit/f0ea743c08e1f05da9cc04081ab329f3517ab9c0 https://salsa.debian.org/installer-team/debian-installer/commit/6fb4c84ceaf3d1bdd64c2fff0eee1e37ba779d1c I've taken the liberty to remove all references to both flavours in various repositories. Please shout if there's anything wrong there! The beep user, network-console: https://salsa.debian.org/installer-team/network-console/commit/f4cb2d43cab66e0a4600476ca1affd85d4e21a5b The others: https://salsa.debian.org/installer-team/base-installer/commit/cc8d251183b02b9730c2bd9cad0a290240878737 https://salsa.debian.org/installer-team/base-installer/commit/1b55df673fd0c4c39887582c4868e172198fe2bc https://salsa.debian.org/installer-team/flash-kernel/commit/15f739427d2b1f1aae4b371304c339e05c59b2d4 https://salsa.debian.org/installer-team/libdebian-installer/commit/5f383dab32fee2f331d07c0261e367602cd18d18 https://salsa.debian.org/installer-team/oldsys-preseed/commit/553bc764412c85dbe31af352af1aa2d0a25f81e4 Cheers, -- Cyril Brulebois (k...@debian.org) <https://debamax.com/> D-I release manager -- Release team member -- Freelance Consultant
signature.asc
Description: PGP signature