A DSA is needed for the following source packages in old/stable. The specific CVE IDs do not need to be listed, they can be gathered in an up-to-date manner from https://security-tracker.debian.org/tracker/source-package/SOURCEPACKAGE when working on an update. Some packages are not tracked here: - Linux kernel (tracking in kernel-sec repo) - Embargoed issues continue to be tracked in separate file. To pick an issue, simply add your uid behind it. If needed, specify the release by adding a slash after the name of the source package. -- apache2 (jmm) -- asterisk Maintainer prepared update for bullseye, needs ping for buster -- condor -- chromium -- djvulibre -- faad2/oldstable (jmm) -- ffmpeg/oldstable (jmm) 4.1.7 fixes a number of bugs, but several further one in the 4.1 branch, reaching out for a 4.1.8 release date -- icu -- linux (carnil) Wait until more issues have piled up, though try to regulary rebase for point releases to more recent v4.19.y versions. -- ndpi -- nodejs (jmm) -- puppetdb (jmm) -- python-pysaml2 (jmm) -- rabbitmq-server -- runc -- salt -- squashfs-tools (carnil) -- tomcat9 Markus Koschany proposed an update for CVE-2021-41079, plus a regression fix from previous CVE-2021-30640 and another non-security fix for #987179, might need a SRM ack. -- varnish -- wordpress (seb) 2021-09-13: Craig Small prepared an upload for bullseye --