Hi,

if anyone is interested, I need help with maintaining the security updates
for nodejs.
https://security-tracker.debian.org/tracker/source-package/nodejs

It's about carefully reading the upstream changelog, identify commits,
backport them
as patches, (and thanks to salsa/debusine tools, builds can be tested
even if you have a low-end laptop), properly mention the CVE and close bugs
in the
changelog, and submit a debdiff to the security team (who eventually
answer, because
they are overbooked) and then upload.

A straightforward and initiative job ;)

Jérémy

PS: please avoid answering to comment on my wording. I'm not a native
english speaker.

Reply via email to