Hi Andrea, On Fri, Aug 08, 2025 at 12:57:53AM +0200, Andrea Pappacoda wrote: > Hi Salvatore, > > On Thu Aug 7, 2025 at 7:09 AM CEST, Salvatore Bonaccorso wrote: > > My suggestion would be: make first a unstable upload with the targeted > > fix (maybe after saturday, given trixie release is just around the > > corner and we should not cause mor work to the release team). Once that > > is in, we can decide if cpp-httplib requires a DSA or a point release is > > enough. > > > > Samewise then for bookworm. > > Is it ok if the upload fixing the CVEs isn't a backport but an update to the > latest upstream release? I've already done so in experimental.
yes of course. My proposal was more targetting if we want to have a ~deb13u1 rebuld for trixie either via security or the first point release. So uploading now the new upstream version is fine in any case. Regards, Salvatore

