Bug#1012174: Inconsistent advice wrt security archive

Richard Lewis <[email protected]>
Newsgroups gmane.linux.debian.devel.www
Message-ID <CAJ3BuoR8OC5BuGXfwEzh8Lg3ZHDP9X+uRPvOTQSNqGUsa-56Qw__536.62565057806$1682951436$gmane$org@mail.gmail.com>
On Tue, 31 May 2022 16:13:27 +0100 Brian Potkin <[email protected]> wrote:
> On Tue 31 May 2022 at 14:58:00 +0200, Julien Cristau wrote:
> > On Tue, May 31, 2022 at 02:26:39PM +0200, David Prévot wrote:

> > > The [errata] advises one to use
> > >
> > >   deb http://security.debian.org/debian-security bullseye-security main contrib non-free
> > >
> > > while the [release-notes] advises
> > >
> > >   deb https://deb.debian.org/debian-security bullseye-security main contrib

> > >   errata: https://www.debian.org/releases/stable/errata#security
> > >   release-notes: https://www.debian.org/releases/stable/amd64/release-notes/ch-information#security-archive
> > >
> > The release-notes version is preferred, as far as scheme and hostname.
>
> There appears to be a consensus in favour of https. For example:
>
>   https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=992692#37

In release-notes the only http:// i could find was in en/upgrading.dbk
(apart from inside xmlns markup)
https://salsa.debian.org/ddp-team/release-notes/-/merge_requests/160
has just been submitted to update this to https

I dont think the 'errata' page above is in the release-notes repository (?)
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.