Hi Sylvain, Roberto, On Wed, Jul 30, 2025 at 12:44 PM Sylvain Beucler <[email protected]> wrote: > So, most of the remaining 23 packages, especially as it's only 1-2 CVEs > for each package, and especially when they are not sponsored, are very > low-priority.
Apologies - just trying to close this thread.. So are we OK with the regression story on upgrades if they're not sponsored? Whilst I still feel a bit odd about it, I don't know what the best economic path forward is. Should we put this in our backlog? Should 1 (or 2) person try to fix them all without adding load to the queue and the team? Or are we OK to simply ignore them? And on the second thread, which got started, can we remind folks to use 25% of their time and fix issues for bookworm (via p-u), which have been fixed via DLA for bullseye? - u
