-
Notifications
You must be signed in to change notification settings - Fork 2
Open
Labels
improvementThis issue or pull request will add or improve functionality, maintainability, or ease of useThis issue or pull request will add or improve functionality, maintainability, or ease of use
Description
💡 Summary
We should consider installing the systemd-resolved package from Debian Backports when both available and appropriate.
Motivation and context
I noticed that systemd-resolved has a version available from bookworm-backports
currently. That got me curious about what was different between the versions so I checked the changelog and noticed that what probably drove the Backports release was Backport patch to fix CVE-2023-7008 (Closes: #1059278)
. Since the Backports release fixes a CVE it seems like it would be worth inclusion.
Implementation notes
This role would possibly need to configure Backports via cisagov/ansible-role-backports to enable this capability.
Metadata
Metadata
Assignees
Labels
improvementThis issue or pull request will add or improve functionality, maintainability, or ease of useThis issue or pull request will add or improve functionality, maintainability, or ease of use