Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Install systemd-resolved from Debian Backports when appropriate #6

Open
mcdonnnj opened this issue May 15, 2024 · 0 comments
Open

Install systemd-resolved from Debian Backports when appropriate #6

mcdonnnj opened this issue May 15, 2024 · 0 comments
Labels
improvement This issue or pull request will add new or improve existing functionality

Comments

@mcdonnnj
Copy link
Member

💡 Summary

We should consider installing the systemd-resolved package from Debian Backports when both available and appropriate.

Motivation and context

I noticed that systemd-resolved has a version available from bookworm-backports currently. That got me curious about what was different between the versions so I checked the changelog and noticed that what probably drove the Backports release was Backport patch to fix CVE-2023-7008 (Closes: #1059278). Since the Backports release fixes a CVE it seems like it would be worth inclusion.

Implementation notes

This role would possibly need to configure Backports via cisagov/ansible-role-backports to enable this capability.

@mcdonnnj mcdonnnj added the improvement This issue or pull request will add new or improve existing functionality label May 15, 2024
@mcdonnnj mcdonnnj changed the title Install systemd-resolve from Debian Backports when appropriate Install systemd-resolved from Debian Backports when appropriate May 21, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
improvement This issue or pull request will add new or improve existing functionality
Projects
None yet
Development

No branches or pull requests

1 participant