Hi, I've been doing Debian LTS security backport work lately (caddy, cjose, git-lfs, libgit2 - real MRs/patches, not just talk: https://salsa.debian.org/go-team/packages/caddy/-/merge_requests/3 is a recent example, 8 CVEs backported to bookworm) and I'd like to put some of that toward docker.io, given the RFH has been open a while.
Rather than a generic offer, I'd rather ask directly: is there a specific slice of the CVE backlog or the dependency tree that's actually the bottleneck right now, or a particular kind of help that's more useful than others? Happy to start small and build up context rather than assuming I know what's needed. Ivo
