Debian Package Tracker
Register | Log in
Subscribe

firefox-esr

Mozilla Firefox web browser - Extended Support Release (ESR)

Choose email to subscribe with

general
  • source: firefox-esr (main)
  • version: 140.14.0esr-2
  • maintainer: Maintainers of Mozilla-related packages (DMD)
  • uploaders: Mike Hommey [DMD]
  • arch: all any
  • std-ver: 3.9.8.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 115.14.0esr-1~deb11u1
  • o-o-sec: 140.14.0esr-1~deb11u1
  • o-o-p-u: 115.14.0esr-1~deb11u1
  • oldstable: 140.12.0esr-1~deb12u1
  • old-sec: 140.14.0esr-1~deb12u1
  • old-p-u: 140.12.0esr-1~deb12u1
  • stable: 140.12.0esr-1~deb13u1
  • stable-sec: 140.14.0esr-1~deb13u1
  • stable-p-u: 140.13.0esr-1~deb13u1
  • testing: 140.13.0esr-2
  • unstable: 140.14.0esr-2
versioned links
  • 78.15.0esr-1~deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 91.13.0esr-1~deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 115.14.0esr-1~deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 115.15.0esr-1~deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 140.12.0esr-1~deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 140.12.0esr-1~deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 140.13.0esr-1~deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 140.13.0esr-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 140.14.0esr-1~deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 140.14.0esr-1~deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 140.14.0esr-1~deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 140.14.0esr-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • firefox-esr (287 bugs: 5, 248, 34, 0)
  • firefox-esr-l10n-ach
  • firefox-esr-l10n-af
  • firefox-esr-l10n-all
  • firefox-esr-l10n-an
  • firefox-esr-l10n-ar
  • firefox-esr-l10n-ast
  • firefox-esr-l10n-az
  • firefox-esr-l10n-be
  • firefox-esr-l10n-bg
  • firefox-esr-l10n-bn
  • firefox-esr-l10n-br
  • firefox-esr-l10n-bs
  • firefox-esr-l10n-ca
  • firefox-esr-l10n-ca-valencia
  • firefox-esr-l10n-cak
  • firefox-esr-l10n-cs
  • firefox-esr-l10n-cy
  • firefox-esr-l10n-da
  • firefox-esr-l10n-de (1 bugs: 0, 1, 0, 0)
  • firefox-esr-l10n-dsb
  • firefox-esr-l10n-el (1 bugs: 0, 1, 0, 0)
  • firefox-esr-l10n-en-ca (1 bugs: 0, 1, 0, 0)
  • firefox-esr-l10n-en-gb (1 bugs: 0, 1, 0, 0)
  • firefox-esr-l10n-eo
  • firefox-esr-l10n-es-ar
  • firefox-esr-l10n-es-cl
  • firefox-esr-l10n-es-es
  • firefox-esr-l10n-es-mx
  • firefox-esr-l10n-et
  • firefox-esr-l10n-eu
  • firefox-esr-l10n-fa
  • firefox-esr-l10n-ff
  • firefox-esr-l10n-fi (2 bugs: 0, 1, 1, 0)
  • firefox-esr-l10n-fr
  • firefox-esr-l10n-fur
  • firefox-esr-l10n-fy-nl
  • firefox-esr-l10n-ga-ie
  • firefox-esr-l10n-gd
  • firefox-esr-l10n-gl (1 bugs: 0, 0, 1, 0)
  • firefox-esr-l10n-gn
  • firefox-esr-l10n-gu-in
  • firefox-esr-l10n-he
  • firefox-esr-l10n-hi-in
  • firefox-esr-l10n-hr
  • firefox-esr-l10n-hsb
  • firefox-esr-l10n-hu
  • firefox-esr-l10n-hy-am
  • firefox-esr-l10n-ia
  • firefox-esr-l10n-id
  • firefox-esr-l10n-is
  • firefox-esr-l10n-it
  • firefox-esr-l10n-ja
  • firefox-esr-l10n-ka
  • firefox-esr-l10n-kab
  • firefox-esr-l10n-kk
  • firefox-esr-l10n-km
  • firefox-esr-l10n-kn
  • firefox-esr-l10n-ko
  • firefox-esr-l10n-lij
  • firefox-esr-l10n-lt
  • firefox-esr-l10n-lv
  • firefox-esr-l10n-mk
  • firefox-esr-l10n-mr
  • firefox-esr-l10n-ms
  • firefox-esr-l10n-my
  • firefox-esr-l10n-nb-no
  • firefox-esr-l10n-ne-np
  • firefox-esr-l10n-nl
  • firefox-esr-l10n-nn-no
  • firefox-esr-l10n-oc
  • firefox-esr-l10n-pa-in
  • firefox-esr-l10n-pl
  • firefox-esr-l10n-pt-br
  • firefox-esr-l10n-pt-pt
  • firefox-esr-l10n-rm
  • firefox-esr-l10n-ro
  • firefox-esr-l10n-ru
  • firefox-esr-l10n-sat
  • firefox-esr-l10n-sc
  • firefox-esr-l10n-sco
  • firefox-esr-l10n-si
  • firefox-esr-l10n-sk
  • firefox-esr-l10n-skr
  • firefox-esr-l10n-sl
  • firefox-esr-l10n-son
  • firefox-esr-l10n-sq
  • firefox-esr-l10n-sr
  • firefox-esr-l10n-sv-se (1 bugs: 0, 0, 1, 0)
  • firefox-esr-l10n-szl
  • firefox-esr-l10n-ta
  • firefox-esr-l10n-te
  • firefox-esr-l10n-tg
  • firefox-esr-l10n-th
  • firefox-esr-l10n-tl
  • firefox-esr-l10n-tr
  • firefox-esr-l10n-trs
  • firefox-esr-l10n-uk
  • firefox-esr-l10n-ur
  • firefox-esr-l10n-uz
  • firefox-esr-l10n-vi
  • firefox-esr-l10n-xh
  • firefox-esr-l10n-zh-cn
  • firefox-esr-l10n-zh-tw
action needed
Marked for autoremoval on 18 September: #1128875 high
Version 140.13.0esr-2 of firefox-esr is marked for autoremoval from testing on Fri 18 Sep 2026. It is affected by #1128875. The removal of firefox-esr will also cause the removal of (transitive) reverse dependencies: debianbuttons, firefox-esr-mobile-config, gnome-kiosk, gosa, gosa-plugins-ldapmanager, gosa-plugins-mailaddress, gosa-plugins-netgroups, gosa-plugins-pwreset, gosa-plugins-rolemanagement, gosa-plugins-sudo, gosa-plugins-systems, phoenix, pybrowsers, reform-tools. You should try to prevent the removal by fixing these RC bugs.
Created: 2026-08-10 Last update: 2026-08-24 09:02
A new upstream version is available: 153.1.0esr high
A new upstream version 153.1.0esr is available, you should consider packaging it.
Created: 2026-07-22 Last update: 2026-08-24 03:03
31 security issues in forky high

There are 31 open security issues in forky.

31 important issues:
  • CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74935: Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74939: Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74940: Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74942: Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74943: Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74944: Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74945: Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74948: Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74953: Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74957: Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74959: Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74960: Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74962: Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74964: Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74965: Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74973: Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74987: Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
  • CVE-2026-74990: Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Created: 2026-08-18 Last update: 2026-08-21 18:02
lintian reports 2 errors and 25 warnings high
Lintian reports 2 errors and 25 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-05-20 Last update: 2026-08-20 03:18
Standards version of the package is outdated. high
The package is severely out of date with respect to the Debian Policy. The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 3.9.8.0).
Created: 2017-06-24 Last update: 2026-08-19 09:20
Fails to build during reproducibility testing normal
A package building reproducibly enables third parties to verify that the source matches the distributed binaries. It has been identified that this source package produced different results, failed to build or had other issues in a test environment. Please read about how to improve the situation!
Created: 2026-05-17 Last update: 2026-08-24 08:01
15 bugs tagged patch in the BTS normal
The BTS contains patches fixing 15 bugs (16 if counting merged bugs), consider including or untagging them.
Created: 2026-08-15 Last update: 2026-08-24 08:00
Depends on packages which need a new maintainer normal
The packages that firefox-esr depends on which need a new maintainer are:
  • hunspell-kk (#879871)
    • Recommends: hunspell-kk
  • ifrench-gut (#1006643)
    • Recommends: myspell-fr-gut
  • uzbek-wordlist (#841696)
    • Recommends: hunspell-uz
Created: 2019-11-22 Last update: 2026-08-24 07:00
AppStream hints: 1 warning for firefox-esr normal
AppStream found metadata issues for packages:
  • firefox-esr: 1 warning
You should get rid of them to provide more metadata about this software.
Created: 2020-01-13 Last update: 2025-04-02 15:31
debian/patches: 23 patches to forward upstream low

Among the 23 debian patches available in version 140.14.0esr-2 of the package, we noticed the following issues:

  • 23 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-08-19 15:02
testing migrations
  • excuses:
    • Migration status for firefox-esr (140.13.0esr-2 to 140.14.0esr-2): Will attempt migration (Any information below is purely informational)
    • Additional info (not blocking):
    • ∙ ∙ Updating firefox-esr will fix bugs in testing: #1128875
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/f/firefox-esr.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • ∙ ∙ 5 days old (needed 5 days)
news
[rss feed]
  • [2026-08-21] Accepted firefox-esr 140.14.0esr-1~deb11u1 (source) into oldoldstable-security (Emilio Pozuelo Monfort)
  • [2026-08-21] Accepted firefox-esr 140.14.0esr-1~deb12u1 (source) into oldstable-security (Mike Hommey)
  • [2026-08-19] Accepted firefox-esr 140.14.0esr-1~deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Mike Hommey)
  • [2026-08-19] Accepted firefox-esr 140.14.0esr-2 (source) into unstable (Mike Hommey)
  • [2026-07-27] firefox-esr 140.13.0esr-2 MIGRATED to testing (Debian testing watch)
  • [2026-07-25] Accepted firefox-esr 140.13.0esr-1~deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Mike Hommey)
  • [2026-07-22] Accepted firefox-esr 140.13.0esr-1~deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Mike Hommey)
  • [2026-07-22] Accepted firefox-esr 140.13.0esr-1~deb11u1 (source) into oldoldstable-security (Emilio Pozuelo Monfort)
  • [2026-07-22] Accepted firefox-esr 140.13.0esr-2 (source) into unstable (Mike Hommey)
  • [2026-07-22] Accepted firefox-esr 140.13.0esr-1~deb12u1 (source) into oldstable-security (Mike Hommey)
  • [2026-07-22] Accepted firefox-esr 140.13.0esr-1 (source) into unstable (Mike Hommey)
  • [2026-06-22] firefox-esr 140.12.0esr-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-19] Accepted firefox-esr 140.12.0esr-1~deb12u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Mike Hommey)
  • [2026-06-19] Accepted firefox-esr 140.12.0esr-1~deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Mike Hommey)
  • [2026-06-18] Accepted firefox-esr 140.12.0esr-1~deb11u1 (source) into oldoldstable-security (Emilio Pozuelo Monfort)
  • [2026-06-17] Accepted firefox-esr 140.12.0esr-1~deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Mike Hommey)
  • [2026-06-17] Accepted firefox-esr 140.12.0esr-1~deb12u1 (source) into oldstable-security (Debian FTP Masters) (signed by: Mike Hommey)
  • [2026-06-16] Accepted firefox-esr 140.12.0esr-1 (source) into unstable (Mike Hommey)
  • [2026-05-26] firefox-esr 140.11.0esr-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-22] Accepted firefox-esr 140.11.0esr-1~deb12u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Mike Hommey)
  • [2026-05-22] Accepted firefox-esr 140.11.0esr-1~deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Mike Hommey)
  • [2026-05-20] Accepted firefox-esr 140.11.0esr-1~deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Mike Hommey)
  • [2026-05-20] Accepted firefox-esr 140.11.0esr-1~deb12u1 (source) into oldstable-security (Debian FTP Masters) (signed by: Mike Hommey)
  • [2026-05-20] Accepted firefox-esr 140.11.0esr-1~deb11u1 (source) into oldoldstable-security (Emilio Pozuelo Monfort)
  • [2026-05-20] Accepted firefox-esr 140.11.0esr-1 (source) into unstable (Mike Hommey)
  • [2026-05-14] firefox-esr 140.10.2esr-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-10] Accepted firefox-esr 140.10.2esr-1~deb12u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Mike Hommey)
  • [2026-05-10] Accepted firefox-esr 140.10.2esr-1~deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Mike Hommey)
  • [2026-05-09] Accepted firefox-esr 140.10.2esr-1~deb11u1 (source) into oldoldstable-security (Emilio Pozuelo Monfort)
  • [2026-05-08] Accepted firefox-esr 140.10.2esr-1~deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Mike Hommey)
  • 1
  • 2
bugs [bug history graph]
  • all: 303 308
  • RC: 6
  • I&N: 257 262
  • M&W: 40
  • F&P: 0
  • patch: 15 16
  • NC: 1
links
  • lintian (2, 25)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots
  • debian patches

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing