Commit 09aa4ef
committed
feat(build): Offload mosquitto maintenance to Debian
Removing downstrem mosquitto techdebt, by deleting
docker/fetch_build_mosquitto.sh
To avoid double downstream maintenance (and future tech debt, the
effort is done at the platform level (in this project the reference
distrib is Debian-12)
As volunteer debian package maintainer, with the help of Debian IoT
team, I have fixed (in 2.0.11-1.2+deb12u2) the security
vulnerabilities reported in the stable version (2.0.11-1 on bookworm).
Later versions of mosquitto in debian-13+ are not affected by mentionned CVE.
Please check related links for more details.
Origin: SiliconLabsSoftware#142
Relate-to: https://www.debian.org/News/2025/2025090602
Relate-to: https://tracker.debian.org/news/1647711/accepted-mosquitto-2011-12deb12u2-source-into-proposed-updates/
Relate-to: https://security-tracker.debian.org/tracker/CVE-2023-28366
Relate-to: https://security-tracker.debian.org/tracker/CVE-2024-3935
Relate-to: https://security-tracker.debian.org/tracker/CVE-2024-8376
Relate-to: https://security-tracker.debian.org/tracker/CVE-2024-10525
Signed-off-by: Philippe Coval <[email protected]>1 parent aa6fabf commit 09aa4ef
1 file changed
+0
-40
lines changedThis file was deleted.
0 commit comments