TODO
====

  * rework debconf handling similar to ca-certificates to only show and run
    newly added mitigations on package upgrades.
  * rework kernel version checks for stable/oldstable etc (i.e. support fixed
    kernel version ranges, rather than one absolute version only).
  * maybe integrate with kernel hooks, so that on kernel-package installation,
    linux-vulnerability-mitigation is executed automatically.
  * maybe add systemd unit on start to set automatic mitigations
  * add remaining manpages.
