Hi,
they are sitting in proposed-updates.
My rationale is as follows: We have the next-point-update.txt and
next-oldstable-point-update.txt to track *potential* candidates for
inclusion in the point release. As long they are not in stable (be it
in the main archive, or security) they are not officially in that
suite.
At point release time uploads might be not accepted last minute,
skipped.
The security-team uses the two files to track such propsoed update,
and we *do* review the list in light of a point release if they get
accepted, if there is change in the CVEs, if something changed, if
there was a followup due to regression, etc ...
It is though crucial that version in poposed updates do not influence
the fixed status of a CVE and this only should happend once the
package is in the main archive or the security archive.
Maybe the idea is just to track the version available, then this might
be an option. Important is that they do not influence the fixed
status, and we really ought to make the tracking only for fixes which
get accepted.
Regards,
Salvatore