Re: Suggestion for the Security Advisories

Rainer Fiebig ([email protected] via blfs-support Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.support
Message-ID <[email protected]>
Am 21.08.26 um 17:53 schrieb Bruce Dubbs ([email protected] via
blfs-support Mailing List):
> On 8/21/26 3:41 AM, Rainer Fiebig ([email protected] via blfs-support
> Mailing List) wrote:
>> Yet another "low priority" suggestion from me:
>>
>> The overwhelming flood of security-issues requires efficient, action
>> oriented handling.  Which means knowing _what_ to do takes precedence
>> over knowing _why_ to do it.  But with the current design, _what_ to do
>> is buried in the description and not particularly easy to recognize.
>> What is more is that the descriptions are not displayed by default.
>>
>> Taking rsync as an example, the current default shows this:
>>
>> ID         Package     DateID         Severity
>> sa-13.0-201     rsync         2026-08-15     Critical
>>
>> Which just tells us that there is a critical problem with rsync but not
>> what to do about it.  For the latter the user would have to dig into the
>> (not displayed) description.
>>
>> So what I suggest is to add a field/column "Fixed with" that offers a
>> clue how the problem can be fixed, without having to care about details.
>> This would look like this:
>>
>> ID         Package     DateID         Severity     Fixed with
>> sa-13.0-201     rsync         2026-08-15     Critical     rsync-3.5.0
>>
>> Here the users knows at once what to do, namely update to the new
>> version (if not done already).
>>
>> If the fix is a patch it would look like this:
>>
>> ID         Package     DateID         Severity     Fixed with
>> sa-14.0-0     kbling        2027-01-01     Critical     patch
>>
>> In this case the user knows that he has to check the description for the
>> patch.
> The fix is implied.

But it is not _displayed_ in the list, only in the description.  Which
is not displayed as the default.  And in the description the fix is not
even formatted in a way that makes it stand out from the rest of the text.

That may be acceptable if you have just one security-issue every other
week or one in a month.  But the security-issues just come pouring down
and it's rather hard to keep up.

In principle, the SAs are a great service.  But in their current form
they provide less help than they could.  This is especially sad as the
improvement would be so easy.

But hey: "your list, your rules"!

Rainer

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-support
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.