Here is another example: https://tracker.debian.org/pkg/golang-github-notaryproject-notation-go
It says '1 security issue in trixie high' but the package has never been part of any stable release. Is there some metadata that is wrong triggering this to happen? The link goes to https://security-tracker.debian.org/tracker/CVE-2024-56138 and it looks okay to me, with no references to trixie or stable. /Simon
signature.asc
Description: PGP signature

