Re: Suggestion for the Security Advisories

Bruce Dubbs ([email protected] via blfs-support Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.support
Message-ID <[email protected]>
On 8/21/26 3:41 AM, Rainer Fiebig ([email protected] via blfs-support Mailing List) wrote:
> Yet another "low priority" suggestion from me:
> 
> The overwhelming flood of security-issues requires efficient, action
> oriented handling.  Which means knowing _what_ to do takes precedence
> over knowing _why_ to do it.  But with the current design, _what_ to do
> is buried in the description and not particularly easy to recognize.
> What is more is that the descriptions are not displayed by default.
> 
> Taking rsync as an example, the current default shows this:
> 
> ID 		Package 	DateID 		Severity
> sa-13.0-201 	rsync 		2026-08-15 	Critical
> 
> Which just tells us that there is a critical problem with rsync but not
> what to do about it.  For the latter the user would have to dig into the
> (not displayed) description.
> 
> So what I suggest is to add a field/column "Fixed with" that offers a
> clue how the problem can be fixed, without having to care about details.
> This would look like this:
> 
> ID 		Package 	DateID 		Severity     Fixed with
> sa-13.0-201 	rsync 		2026-08-15 	Critical     rsync-3.5.0
> 
> Here the users knows at once what to do, namely update to the new
> version (if not done already).
> 
> If the fix is a patch it would look like this:
> 
> ID 		Package 	DateID 		Severity     Fixed with
> sa-14.0-0 	kbling		2027-01-01 	Critical     patch
> 
> In this case the user knows that he has to check the description for the
> patch.
The fix is implied.

In almost every case, the fix is to update to the latest stable release.
In the rare case that the fix is a patch, then the solution is to
look at the appropriate page in the development version of the relevant
book,

   -- Bruce

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-support
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.