Hi,

Chris Hofstädtler <[email protected]> (2026-07-23):
> currently server systems installed with the default installation 
> method tend to keep running programs affected by bugs (incl. 
> security vulnerabilities): even when package upgrades are applied, 
> users are unaware that they need to restart the affected services.
> 
> Additionally it's hard to tell which services are affected, f.e. 
> when the security fix is in a shared library.
> 
> Please consider shipping needrestart by default - I thus propose 
> overriding the priority to standard.

For (my part of) debian-boot@, no objections. I'm definitely not an
elephant but I don't recall the last time we actually added something
to standard, only stuff getting removed from it. I'm adding debian-cd@
for information (and maybe action) accordingly.

> I hope needrestart is also fine for desktop installations.

That looks like a good question, does it add anything to e.g. specific
package management/upgrade mechanisms, is that a no-op because they
already do their own thing, or could it interfere? (I have needrestart
on my Debian 12 — oops, time flies — laptop, I'm using GNOME there,
but I'm using apt-get for everything sysadmin-related, so I really
have no idea at this point.)


Cheers,
-- 
Cyril Brulebois ([email protected])            <https://debamax.com/>
D-I release manager -- Release team member -- Freelance Consultant

Attachment: signature.asc
Description: PGP signature

Reply via email to