• Bug#1031046: Request to close

    From Jonas Smedegaard@21:1/5 to All on Mon Apr 14 11:20:01 2025
    Hi Chris,

    Quoting Chris Maj via Pkg-voip-maintainers (2025-04-14 10:01:29)
    To address OP's security concerns -- there's been only 12 CVEs upstream in 2023/2024, owing to much improved processes, automated tests, etc. These continue to be patched in regular upstream releases once or twice a month.

    To address chief maintainer's concerns -- there's been several volunteers over the past year on the mailing list.

    What is needed is not promises but demonstrated praxis.

    We need a team that has demonstrated investing the needed skills and
    time to backport *any* CVEs *at all*, before we can commit to handling
    such expected rate of 12 CVEs per year.

    To avoid misunderstanding: I am *not* blaming the volunteers that have
    chimed in, specifically. I really don't know if they are all super enthusiastic and super skilled and have all simply waited for me to say
    "go!" in the appropriate way for us to blossom as a functional team.
    Whatever the cause, the team is not yet functional, and what the
    security team requested by filing this bugreport is that we *first*
    demonstrate capability in handling CVEs, and only *then* re-add the
    package to stable Debian.

    Also, freeze is tomorrow, and it takes at a minimum 3 days for a package
    to enter testing, so even if we somehow demonstrated capability today,
    we would still be too late to include it.

    Thanks for the interest,


    - Jonas

    --
    * Jonas Smedegaard - idealist & Internet-arkitekt
    * Tlf.: +45 40843136 Website: http://dr.jones.dk/
    * Sponsorship: https://ko-fi.com/drjones

    [x] quote me freely [ ] ask before reusing [ ] keep private

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Chris Maj@21:1/5 to pkg-voip-maintainers@alioth-lists.d on Mon Jul 7 04:10:01 2025
    Thanks y'all for the excellent ideas, kind words and generous support -- looking forward to helping steward the Asterisk package along with you on
    the journey in to backports soon after trixie is released :-)

    [image: Sangoma]
    [image: LinkedIn] <https://www.linkedin.com/company/sangoma> [image: X] <https://x.com/sangoma> [image: Facebook]
    <https://www.facebook.com/Sangoma/> [image: YouTube] <https://www.youtube.com/user/SangomaTechnologies/>
    Chris Maj Open Source Solutions Advocate

    P: +1.920.574.9568

    E: cmaj@sangoma.com

    W: www.sangoma.com <https://sangoma.com/>
    [image: Sangoma]


    On Thu, Jun 12, 2025 at 8:29 AM Benjamin Renard via Pkg-voip-maintainers < pkg-voip-maintainers@alioth-lists.debian.net> wrote:

    Hi,

    @Chris, do you think you could make the necessary arrangements to have
    your version of Asterisk for Trixie pushed into Debian Testing? You are certainly in the best position, with the help of your team at Sangoma and other volunteers who have offered their assistance here and elsewhere, to make this a reality. This step would not only benefit the current user base but also demonstrate the commitment and capability of the community to maintain and promptly update the package, particularly in response to CVEs.

    By including the Asterisk in Debian testing, we can showcase the active engagement of the user community, potentially facilitating its inclusion in trixie-backports initially, and finally in the next stable release of
    Debian. This would ensure that Debian users have access to up-to-date and secure Asterisk packages.

    I fear that without progress on this matter, we may find with numerous Asterisk instances stuck on Debian Bullseye, which will no longer be maintained after August 2026 with the end of LTS. Additionally, there could be a proliferation of individual solutions to migrate to Trixie, involving local builds that are difficult to keep secure. Having up-to-date packages maintained in testing (and ideally in trixie-backports) would provide an "official" solution, demonstrating the desire to see the inclusion of Asterisk return to Debian Forky.

    Thank you all!

    Best regards,

    --
    Benjamin Renard - Easter-eggs
    44-46 rue de l'Ouest - 75014 Paris - France - Métro Gaité
    Phone: +33 (0) 1 43 35 00 37 - mailto:brenard@easter-eggs.com <brenard@easter-eggs.com>



    <div dir="ltr"><div><div class="gmail_default" style="font-family:monospace">Thanks y&#39;all for the excellent ideas, kind words and generous support -- looking forward to helping steward the Asterisk package along with you on the journey in to
    backports soon after trixie is released :-)</div><br clear="all"></div><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><table style="width:100%;font-family:Trebuchet,system-ui,-apple-system,BlinkMacSystemFont,&#
    39;Segoe UI&#39;,Roboto,Oxygen,Ubuntu,Cantarell,&#39;Open Sans&#39;,&#39;Helvetica Neue&#39;,sans-serif">
    <tbody>
    <tr>
    <td style="width:86px;vertical-align:baseline;padding-right:8px;text-align:center">
    <img style="width:76px;height:76px;border-radius:50%;display:inline-block" src="https://gravatar.com/userimage/254988292/619dd3a722855671ad40841d775d890b.jpeg?size=256&amp;cache=1748634518411" alt="Sangoma">
    <div>
    <a style="display:inline-block" href="https://www.linkedin.com/company/sangoma" target="_blank"><img src="https://apps3.sangoma.com/esign-in.png" alt="LinkedIn" style="width:14px;height:14px"></a>
    <a style="display:inline-block" href="https://x.com/sangoma" target="_blank"><img src="https://apps3.sangoma.com/esign-x.png" alt="X" style="width:14px;height:14px"></a>
    <a style="display:inline-block" href="https://www.facebook.com/Sangoma/" target="_blank"><img src="https://apps3.sangoma.com/esign-f.png" alt="Facebook" style="width:14px;height:14px"></a>
    <a style="display:inline-block" href="https://www.youtube.com/user/SangomaTechnologies/" target="_blank"><img src="https://apps3.sangoma.com/esign-yt.png" alt="YouTube" style="width:14px;height:14px"></a>
    </div>
    </td>
    <td>
    <h1 style="font-size:20px;margin:0px;padding:0px;line-height:normal;font-weight:500;color:rgb(124,40,112)">Chris Maj</h1>
    <h2 style="font-size:12px;padding:0px 0px 8px;line-height:normal;color:rgb(0,18,33);margin:0px">Open Source Solutions Advocate</h2>
    <p style="font-size:12px;color:rgb(0,18,33);margin:0px">
    <span style="color:#158fcf;font-weight:600">P: </span>
    <a style="color:rgb(0,0,0)!important" href="tel:+1.920.574.9568" target="_blank">+1.920.574.9568</a>
    </p>
    <p style="font-size:12px;color:rgb(0,18,33);margin:4px 0px">
    <span style="color:#158fcf;font-weight:600">E: </span>
    <a style="color:rgb(0,0,0)!important" href="mailto:cmaj@sangoma.com" target="_blank">cmaj@sangoma.com</a>
    </p>
    <p style="font-size:12px;color:rgb(0,18,33);margin:0px">
    <span style="color:#158fcf;font-weight:600">W: </span>
    <a style="color:rgb(0,0,0)!important" href="https://sangoma.com/" target="_blank">www.sangoma.com</a>
    </p>
    <img src="https://apps3.sangoma.com/esign-label.png" alt="Sangoma" style="padding-top:8px;width:100%;max-width:260px">
    </td>
    </tr>
    </tbody></table></div></div></div><br></div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Thu, Jun 12, 2025 at 8:29 AM Benjamin Renard via Pkg-voip-maintainers &lt;<a href="mailto:pkg-voip-
    maintainers@alioth-lists.debian.net">pkg-voip-maintainers@alioth-lists.debian.net</a>&gt; wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><u></u>





    <div>
    <p dir="auto">Hi,</p>
    <p dir="auto">@Chris, do you think you could make the necessary
    arrangements to have your version of Asterisk for Trixie pushed
    into Debian Testing? You are certainly in the best position, with
    the help of your team at Sangoma and other volunteers who have
    offered their assistance here and elsewhere, to make this a
    reality. This step would not only benefit the current user base
    but also demonstrate the commitment and capability of the
    community to maintain and promptly update the package,
    particularly in response to CVEs.</p>
    <p dir="auto">By including the Asterisk in Debian testing, we can
    showcase the active engagement of the user community, potentially
    facilitating its inclusion in trixie-backports initially, and
    finally in the next stable release of Debian. This would ensure
    that Debian users have access to up-to-date and secure Asterisk
    packages.</p>
    <p dir="auto">I fear that without progress on this matter, we may
    find with numerous Asterisk instances stuck on Debian Bullseye,
    which will no longer be maintained after August 2026 with the end
    of LTS. Additionally, there could be a proliferation of individual
    solutions to migrate to Trixie, involving local builds that are
    difficult to keep secure. Having up-to-date packages maintained in
    testing (and ideally in trixie-backports) would provide an
    &quot;official&quot; solution, demonstrating the desire to see the inclusion
    of Asterisk return to Debian Forky.</p>
    <p dir="auto">Thank you all!</p>
    <p dir="auto">Best regards,</p>
    <div id="m_9091081637081285320grammalecte_menu_main_button_shadow_host" style="width:0px;height:0px"></div>
    <pre cols="72">--
    Benjamin Renard - Easter-eggs
    44-46 rue de l&#39;Ouest - 75014 Paris - France - Métro Gaité
    Phone: +33 (0) 1 43 35 00 37 - <a href="mailto:brenard@easter-eggs.com" target="_blank">mailto:brenard@easter-eggs.com</a></pre>
    </div>

    </blockquote></div>

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)