Re: Suggestion for the Security Advisories
| Newsgroups | gmane.linux.lfs.beyond.support |
|---|---|
| Message-ID | <[email protected]> |
Am 21.08.26 um 17:53 schrieb Bruce Dubbs ([email protected] via blfs-support Mailing List): > On 8/21/26 3:41 AM, Rainer Fiebig ([email protected] via blfs-support > Mailing List) wrote: >> Yet another "low priority" suggestion from me: >> >> The overwhelming flood of security-issues requires efficient, action >> oriented handling. Which means knowing _what_ to do takes precedence >> over knowing _why_ to do it. But with the current design, _what_ to do >> is buried in the description and not particularly easy to recognize. >> What is more is that the descriptions are not displayed by default. >> >> Taking rsync as an example, the current default shows this: >> >> ID Package DateID Severity >> sa-13.0-201 rsync 2026-08-15 Critical >> >> Which just tells us that there is a critical problem with rsync but not >> what to do about it. For the latter the user would have to dig into the >> (not displayed) description. >> >> So what I suggest is to add a field/column "Fixed with" that offers a >> clue how the problem can be fixed, without having to care about details. >> This would look like this: >> >> ID Package DateID Severity Fixed with >> sa-13.0-201 rsync 2026-08-15 Critical rsync-3.5.0 >> >> Here the users knows at once what to do, namely update to the new >> version (if not done already). >> >> If the fix is a patch it would look like this: >> >> ID Package DateID Severity Fixed with >> sa-14.0-0 kbling 2027-01-01 Critical patch >> >> In this case the user knows that he has to check the description for the >> patch. > The fix is implied. But it is not _displayed_ in the list, only in the description. Which is not displayed as the default. And in the description the fix is not even formatted in a way that makes it stand out from the rest of the text. That may be acceptable if you have just one security-issue every other week or one in a month. But the security-issues just come pouring down and it's rather hard to keep up. In principle, the SAs are a great service. But in their current form they provide less help than they could. This is especially sad as the improvement would be so easy. But hey: "your list, your rules"! Rainer -- http://lists.linuxfromscratch.org/sympa/info/blfs-support Unsubscribe: See the above information page