vcswatch reports that
there is an error with this package's VCS, or the debian/changelog file inside
it. Please check the error shown below and try to fix it. You might have
to update the VCS URL in the debian/control file to point to the correct
repository.
fatal: unable to access 'https://salsa.debian.org/openstack-team/services/ironic-python-agent.git/': The requested URL returned error: 500
Among the 1 debian patch
available in version 12.0.0-2 of the package,
we noticed the following issues:
1 patch
where the metadata indicates that the patch has not yet been forwarded
upstream. You should either forward the patch upstream or update the
metadata to document its real status.
3 issues left for the package maintainer to handle:
CVE-2026-43003:
(needs triaging)
An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.
CVE-2026-54422:
(needs triaging)
In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.
CVE-2026-66138:
(needs triaging)
In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell.
Migration status for ironic-python-agent (11.5.0-5 to 12.0.0-2): Waiting for test results or another package, or too young (no action required now - check later)