Skip to content
Discussion options

You must be logged in to vote

The arch=source just means the package.name and version refers to the source package, not the binary package. Let's take curl for example: https://launchpad.net/ubuntu/+source/curl this is the link to the source package, and you can see multiple binary packages (what you install with apt install listed under it (curl, curl-dbgsym, libcurl4-openssl-dev...). And looking at a OSV entry: https://osv.dev/vulnerability/USN-5495-2, the package name there refers to the source. For Ubuntu advisories, the database specific field lists the binary packages.

  1. No, it means all architectures it compiles to are affected. We generally don't have architecture specific advisory records.
  2. Because most vulnera…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@alistair-mclean
Comment options

Answer selected by alistair-mclean
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants