]> git.ipfire.org Git - thirdparty/bind9.git/commit
Explicit sub-steps for assessing -S and EOL
authorBen Scott <bscott@isc.org>
Wed, 10 Jun 2026 19:56:00 +0000 (15:56 -0400)
committerBen Scott <bscott@isc.org>
Wed, 10 Jun 2026 20:46:29 +0000 (16:46 -0400)
commit4fac2a92db4d41a481c8e899bb24c378f801ea54
treeed7efbc52185fcb32a5e469b7b0da93df9cacd24
parenta026d31095a29a99c396b1fe3e380f3467120a22
Explicit sub-steps for assessing -S and EOL

For the step where we assess which product versions/branches are
vulnerable to the flaw, add explicit subordinate steps for assessing
Special Subscriber -S Preview edition, and end-of-life versions that
are still received paid fixes.

While we have GitLab labels to indicate affected versions, there is no
satisfactory mechanism in place to indicate that assessment of all
versions is complete, and thus anything not labeled as affected can be
considered immune.  Explicit checklist steps will allow others to see
when assessment is complete.

Per the following discussions:

https://zulip.isc.org/#narrow/channel/4-bind9/topic/Unaffected.20labels.20for.20vulnerability.20issues/near/25643

https://zulip.isc.org/#narrow/channel/4-bind9/topic/CVE.20checklist.20updates/near/26307
.gitlab/issue_templates/Internal_use_only-CVE.md