On Sat, Feb 28, 2026 at 11:54:27AM +0100, Salvatore Bonaccorso wrote:
> [...]
> CVE-2024-36600[0]:
> [...]
> [2] 
> https://github.com/libcdio/libcdio/commit/417478a7474af41c27ab3f876f31783fa06a5dbc

This commit is part of upstream's most recent stable release 2.3.0, as
debian-bts-link has already indicated.

However, uscan quite distractingly doesn't find this version but finds
2.3.0.rc1 instead. Updating debian/watch to

| Version: 5
| Template: Github
| Owner: libcdio
| Project: libcdio
| Version-Type: STABLE_VERSION

allows uscan to detect 2.3.0.

HTH,
Flo

Attachment: signature.asc
Description: PGP signature

Reply via email to