Definitely - happy to take a piece of that on. Checked the security tracker first: bookworm currently has 13 open CVEs (CVE-2026-42306, -41568, -41567, -34040, -33997, -33748, -33747, and a few older ones back to 2024-24557), trixie's already clean once the +deb13u1 in proposed-updates migrates.
I also found wip/rt/security on the Salsa repo - 268 commits ahead of debian/bookworm, so clearly a real, substantial effort, not something I should just barge into blind. Before I start: is that branch meant to become the actual next bookworm upload (in which case I'd rather help push specific pieces of it forward than duplicate work), or would a smaller, CVE-only patch set on top of the current bookworm as it ships now be more useful and shippable sooner - closer to how I've been doing the other LTS backports this week? Either way works for me - just want to point effort where it actually helps rather than guess. Ivo

