Suggestion for the Security Advisories

Rainer Fiebig ([email protected] via blfs-support Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.support,gmane.linux.lfs.support
Message-ID <[email protected]>
Yet another "low priority" suggestion from me:

The overwhelming flood of security-issues requires efficient, action
oriented handling.  Which means knowing _what_ to do takes precedence
over knowing _why_ to do it.  But with the current design, _what_ to do
is buried in the description and not particularly easy to recognize.
What is more is that the descriptions are not displayed by default.

Taking rsync as an example, the current default shows this:

ID 		Package 	DateID 		Severity
sa-13.0-201 	rsync 		2026-08-15 	Critical

Which just tells us that there is a critical problem with rsync but not
what to do about it.  For the latter the user would have to dig into the
(not displayed) description.

So what I suggest is to add a field/column "Fixed with" that offers a
clue how the problem can be fixed, without having to care about details.
This would look like this:

ID 		Package 	DateID 		Severity     Fixed with
sa-13.0-201 	rsync 		2026-08-15 	Critical     rsync-3.5.0

Here the users knows at once what to do, namely update to the new
version (if not done already).

If the fix is a patch it would look like this:

ID 		Package 	DateID 		Severity     Fixed with
sa-14.0-0 	kbling		2027-01-01 	Critical     patch

In this case the user knows that he has to check the description for the
patch.

OK, that's it.  Thanks.

Rainer


-- 
The truth always turns out to be simpler than you thought.
Richard Feynman

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-support
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.