A DSA is needed for the following source packages in old/stable. The specific CVE IDs do not need to be listed, they can be gathered in an up-to-date manner from https://security-tracker.debian.org/tracker/source-package/SOURCEPACKAGE when working on an update. Some packages are not tracked here: - Linux kernel (tracking in kernel-sec repo) - Embargoed issues continue to be tracked in separate file. To pick an issue, simply add your uid behind it. If needed, specify the release by adding a slash after the name of the source package. -- chromium -- docker.io (jmm) Packages rejected due to Built-Using on golang-github-prometheus-common, ftp-master team contacted. -- ffmpeg (jmm) -- fwupd -- jruby/oldstable -- libopenmpt -- knot-resolver/stable Santiago Ruano Rincón proposed a debdiff for review -- linux (carnil) Wait until more issues have piled up -- mercurial/oldstable -- nss/oldstable (jmm) Roberto proposed an update including fixes for CVE-2018-12404 and CVE-2018-18508 -- php7.0/oldstable -- php7.3/stable -- poppler (jmm) -- rails Sylvain Beucler proposed to help for the update -- ruby2.5/stable Utkarsh Gupta proposed to work on an update -- squid3/oldstable -- teeworlds/stable (jmm) -- trafficserver -- xcftools Hugo proposed to work on this update --