Open
Description
Given that Ubuntu's policy is to only provide "Best effort" updates to packages outside of the "Main" repository we should consider removing as many as possible from the Noble stemcell so that we don't end up with unpatched CVEs late in the stemcell lifecycle[1]. See this article on Ubuntu's ESM for more context.
Currently on Jammy the packages not in the "Main" repository are:
clang
clang-14
dnsutils
grub2
ifupdown
libclang-common-14-dev
libclang-cpp14
libclang1-14
libobjc-11-dev:amd64
libobjc4:amd64
linux-modules-6.5.0-21-genericlinux-modules-extra-6.5.0-21-genericllvm-14-linker-tools
module-assistant
resolvconf
rng-tools-debian
runit
scsitools
sysuser-helper
traceroute
[1] The traceroute
package, in the "Universe" repository, has a reported CVE which is not patched even though Jammy is still within its LTS support window.
Metadata
Metadata
Assignees
Labels
No labels
Type
Projects
Status
Pending Review | Discussion