Re: No GLSA since January?!?

Alex Legler <[email protected]> Fri, 26 Aug 2011 20:44:06 +0200
Newsgroups gmane.linux.gentoo.security
Message-ID <4785038.vCXUPsJWHB@neon>
On Friday 26 August 2011 15:22:40 Daniel A. Avelino wrote:
> > When I think about automation, I had in mind something that could help
> 
> developers to find
> vulnerabilities in a more fast way [searching and confronting CVE, for
> example] and  start a
> "call for solution" process. I work with solutions of this type for WEB
> vulnerabilities discover
> and some tools are very interesting to reduce the correction time.
> 

We already use CVE as one of our sources of vulnerability intelligence. 
Finding issues is also not the real issue here.
Also, actual issue correction is not our job, it's the responsibility of the 
package maintainer.

Can you share details about the utilities you are using?

Alex

-- 
Alex Legler <[email protected]>
Gentoo Security / Ruby
signature.asc (application/pgp-signature, 198 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.18 (GNU/Linux)

iEYEABECAAYFAk5X6XYACgkQk+oqhfPAZGnyaQCeLvXv8ESjOm6C0TmSJghN4Nm8
NG8AoJebFZn9FhV2RAidgsHT+stZl2R9
=oVkn
-----END PGP SIGNATURE-----