Skip to content

Commit 09aa4ef

Browse files
committed
feat(build): Offload mosquitto maintenance to Debian
Removing downstrem mosquitto techdebt, by deleting docker/fetch_build_mosquitto.sh To avoid double downstream maintenance (and future tech debt, the effort is done at the platform level (in this project the reference distrib is Debian-12) As volunteer debian package maintainer, with the help of Debian IoT team, I have fixed (in 2.0.11-1.2+deb12u2) the security vulnerabilities reported in the stable version (2.0.11-1 on bookworm). Later versions of mosquitto in debian-13+ are not affected by mentionned CVE. Please check related links for more details. Origin: SiliconLabsSoftware#142 Relate-to: https://www.debian.org/News/2025/2025090602 Relate-to: https://tracker.debian.org/news/1647711/accepted-mosquitto-2011-12deb12u2-source-into-proposed-updates/ Relate-to: https://security-tracker.debian.org/tracker/CVE-2023-28366 Relate-to: https://security-tracker.debian.org/tracker/CVE-2024-3935 Relate-to: https://security-tracker.debian.org/tracker/CVE-2024-8376 Relate-to: https://security-tracker.debian.org/tracker/CVE-2024-10525 Signed-off-by: Philippe Coval <philippe.coval@silabs.com>
1 parent aa6fabf commit 09aa4ef

File tree

1 file changed

+0
-40
lines changed

1 file changed

+0
-40
lines changed

docker/fetch_build_mosquitto.sh

Lines changed: 0 additions & 40 deletions
This file was deleted.

0 commit comments

Comments
 (0)