Hi Tobi, On Tue, Aug 27, 2024 at 09:51:41PM +0200, Salvatore Bonaccorso wrote: > Hi Tobi, > > On Sat, Jun 22, 2024 at 08:46:39PM +0200, Salvatore Bonaccorso wrote: > > Hi Tobi, > > > > On Wed, Feb 21, 2024 at 08:00:42AM +0000, Jonathan Wiltshire wrote: > > > Control: tag -1 moreinfo > > > > > > Hi, > > > > > > On Sat, Oct 28, 2023 at 05:58:38PM +0200, Tobias Frost wrote: > > > > Backporting the fixes is of course possible, but bears a significant > > > > risk for regression, therefor I would prefer to use the new upstream > > > > version, given also that upstream changes are only a few and fixing > > > > also a few bugs that would be nice to be fixed. > > > > > > It's a balancing act, as always. I'm OK with new upstream releases if they > > > are small enough to sensibly review (or an upstream with a good trusted > > > history, which I don't yet have for freerdp2). If you think a new upstream > > > is reasonable, let's see how it looks. > > > > > > Either way we need a source debdiff please. > > > > Did you saw the followup question from Jonathan? > > Friendly ping :). Note we are late for the 12.7 point release now, but > it still should ideally make it for 12.8.
Friendly ping (but I guess we might miss again 12.9 now for it as window for next point release is closing upcoming weekend already). it would be good to see those CVEs addressed in a point release for bookworm. Regards, Salvatore