Skip to content

Install systemd-resolved from Debian Backports when appropriate #6

@mcdonnnj

Description

@mcdonnnj

💡 Summary

We should consider installing the systemd-resolved package from Debian Backports when both available and appropriate.

Motivation and context

I noticed that systemd-resolved has a version available from bookworm-backports currently. That got me curious about what was different between the versions so I checked the changelog and noticed that what probably drove the Backports release was Backport patch to fix CVE-2023-7008 (Closes: #1059278). Since the Backports release fixes a CVE it seems like it would be worth inclusion.

Implementation notes

This role would possibly need to configure Backports via cisagov/ansible-role-backports to enable this capability.

Metadata

Metadata

Assignees

No one assigned

    Labels

    improvementThis issue or pull request will add or improve functionality, maintainability, or ease of use

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions