Hi David, On Sat, Aug 29, 2026 at 04:19:16PM +0200, David Prévot wrote: > Package: release.debian.org > Severity: normal > Tags: trixie > X-Debbugs-Cc: [email protected], Debian Security Team > <[email protected]> > Control: affects -1 + src:composer > User: [email protected] > Usertags: pu > > Hi, > > I’d like to fix five security issues that are not worth a DSA in the > next point release (four are marked as no-dsa, the fifth one has no CVE > assigned).
The fifth one (GHSA-rvx4-ffvw-m9q3), now has as well a CVE, it is CVE-2026-84361. Regards, Salvatore

