A new upstream version 2.11 is available, you should consider packaging it.
debian/patches: 1 patch with invalid metadata, 5 patches to forward upstream
high
Among the 11 debian patches
available in version 1:2.10+dfsg-2 of the package,
we noticed the following issues:
1 patch with
invalid metadata that ought to be fixed.
5 patches
where the metadata indicates that the patch has not yet been forwarded
upstream. You should either forward the patch upstream or update the
metadata to document its real status.
1 issue left for the package maintainer to handle:
CVE-2024-28168:
(needs triaging)
Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: 2.9. Users are recommended to upgrade to version 2.10, which fixes the issue.