A DSA is needed for the following source packages in old/stable. The specific CVE IDs do not need to be listed, they can be gathered in an up-to-date manner from https://security-tracker.debian.org/tracker/source-package/SOURCEPACKAGE when working on an update. Some packages are not tracked here: - Linux kernel (tracking in kernel-sec repo) - Embargoed issues continue to be tracked in separate file. To pick an issue, simply add your uid behind it. If needed, specify the release by adding a slash after the name of the source package. -- curl (ghedo) -- evince/oldstable -- glusterfs/oldstable -- graphicsmagick -- jruby/oldstable -- libexif (carnil) -- libidn2/stable Testpackages: https://people.debian.org/~carnil/tmp/libidn2/ but appears to generate broken manpages. -- libopenmpt -- linux (carnil) Wait until more issues have piled up -- mercurial/oldstable -- nodejs -- nss/oldstable (jmm) Roberto proposed an update including fixes for CVE-2018-12404 and CVE-2018-18508 -- openjdk-8 (jmm) -- php7.0 -- php7.3 -- poppler (jmm) -- prosody-modules Maintainer preparing updates -- python-reportlab (hle) -- qemu Maintainer working on updates -- smarty3/oldstable -- spamassassin Maintainer is preparing updates -- squid3/oldstable -- tiff/oldstable -- xcftools (hle) --