Here is another example:

https://tracker.debian.org/pkg/golang-github-notaryproject-notation-go

It says '1 security issue in trixie high' but the package has never been
part of any stable release.

Is there some metadata that is wrong triggering this to happen?

The link goes to
https://security-tracker.debian.org/tracker/CVE-2024-56138 and it looks
okay to me, with no references to trixie or stable.

/Simon

Attachment: signature.asc
Description: PGP signature

Reply via email to