Re: No GLSA since January?!?

Christian Kauhaus <[email protected]> Sat, 27 Aug 2011 10:49:09 +0200
Newsgroups gmane.linux.gentoo.security
Message-ID <[email protected]>
Am 26.08.2011 20:08, schrieb Kevin Bryan:
> SECURITY_FIXES=3D"<www-plugins/adobe-flash-10.1.102.64"
> SECURITY_REF=3D"CVE:2010-2169 http://..."
> SECURITY_BUG=3D"343089"
> SECURITY_IMPACT=3D"remote"

Your idea sounds interesting and could lead to very cool technology like =
the=20
'ACCEPT_RISKS=3D"..."' variable mentioned elsewhere in this thread.

But it does not solve a major part of the use case. In my opinion, we nee=
d to=20
get notifications about security risks over an independent channel withou=
t=20
having to update the portage tree.

For me (and the rest of my company) the greatest advantage of Gentoo over=
=20
other distributions it it's "continuous integration" approach. Updates ge=
t=20
committed to the portage tree continuously over time and administrators a=
re=20
completely free on how often and when they update their systems. This is=20
great. But given I have an installed base and I have no reason to update =
the=20
portage tree now, I need a reliable information about "this package is=20
borked". Then I should go for update as fast as possible of course. :-)

So in consequence I would appreciate to have both mechanisms: a timely=20
up-front notification via GLSAs (probably more brief than the past ones) =
and=20
some sort of security masking.

Regards

Christian

--=20
Dipl.-Inf. Christian Kauhaus <>< =C2=B7 [email protected] =C2=B7 systems admi=
nistration
gocept gmbh & co. kg =C2=B7 forsterstra=C3=9Fe 29 =C2=B7 06112 halle (saa=
le) =C2=B7 germany
http://gocept.com =C2=B7 tel +49 345 1229889 11 =C2=B7 fax +49 345 122988=
9 1
Zope and Plone consulting and development