Bug#1012174: Inconsistent advice wrt security archive

David Prévot <[email protected]>
Newsgroups gmane.linux.debian.devel.www
Message-ID <YpYJfwk2EkgriXCX__42980.9969545872$1654000228$gmane$org@persil.tilapin.org>
Package: www.debian.org,release-notes
Severity: normal
X-Debbugs-Cc: [email protected]

Hi teams,

The [errata] advises one to use 

  deb http://security.debian.org/debian-security bullseye-security main contrib non-free

while the [release-notes] advises

  deb https://deb.debian.org/debian-security bullseye-security main contrib

Even if both will have the same result (the last time a non-free package
was uploaded to the security archive may have been during Etch), having
two different official advice makes it difficult in some situation
(“what should we actually use?”). Is the use of HTTPS via deb.d.o
preferable over HTTP via security.d.o? If so maybe the errata should be
updated, if it’s the other way around, the realease-notes should be
updated.

  errata: https://www.debian.org/releases/stable/errata#security
  release-notes: https://www.debian.org/releases/stable/amd64/release-notes/ch-information#security-archive

Regards

David
signature.asc (application/pgp-signature, 488 B)
-----BEGIN PGP SIGNATURE-----

iQEzBAABCAAdFiEEeHVNB7wJXHRI941mBYwc+UT2vTwFAmKWCX4ACgkQBYwc+UT2
vTx42gf+JaN91C0v5Tf5GzOs/iLm3GGXr2aXCCg+TfTzSac/KEGw1aymdDtxs7CR
Et8QGuGVgHu5ctcZUDiGm6zdYFo4vt7AkTJRwOmJKA1y4WNN0b3EBHGXVOd+N1aW
Yu/ZrunkXsPkVERmmfmCLFCfHLhVL2KR35uJEHmeKUH6BHDwb0GIiLfeKM0NMHe3
0JtRb7NvX2hz5DvxIC7YZjL5t7TZx/TvTfvk6uqMznU3++rpc6Kx83URaQQgVfzb
LjlMKy8DEmqVShrr1uVWQhxCWsZLZVWCqQUJLqvHlu9C/mu7CC0DiUtheq9/btkK
Oy0O0sW9Atf8u3cB+6Uq0y6/sQNQsg==
=Yer6
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.