Re: [Security-Discuss] Re: [Security Announce] MDKSA-2005:113 - Updated clamav packages fix vulnerability

Vincent Danen <vdanen-4qZELD6FgxhWk0Htik3J/[email protected]> Tue, 12 Jul 2005 13:04:19 -0600
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On 12-Jul-05, at 12:30 PM, Andreas Radke wrote:

>>> wouldn't it make sense in the case of this package, to update to   
>>> the latest
>>> stable version?
>>> Clamav complains about being too old and actually lacks   
>>> functionality when
>>> older versions are used...
>>>
>>> Just a thought.
>>>
>>
>>
>> Thanks for the thought, but no.  It actually wouldn't make sense.   
>> We  have an established policy that has been noted many *many*  
>> times that  we patch packages rather than update to the latest and  
>> greatest so as  to prevent regressions or rebuilds in other  
>> packages that require  what we're updating.
>>
>>
> I think it´s time to think about this policy again. With the  
> upcoming longer product lifetime I do see good reasons for real  
> upgrades.

What longer product lifetime?  Only the corporate products are  
getting longer life.  The 2006 version of Mandrake will still have a  
year of full updates and 6mos of base support after that.  It's no  
different from today.  Only the Corp/MNF products are getting longer  
lifetimes and you must purchase the products in order to gain access  
to the updates.

> Resourses are no good argument for a commercial produkt. I would  
> accept this for a real community distribution but not for a payed one.
>
> So why you have the ressources to release every 2 months a club  
> release only for eyecandy reasons like latest kde?

Two different "divisions".  Club has it's resources and developers,  
stable updates/support has it's own.

> It´s becoming hard to understand your policy.

Feel free to ask management for clarification.  I can only work with  
what I have.  I have absolutely no knowledge, intuition, comments,  
etc. on how other parts of the company work.  I have my own little  
job and trust me, it's enough that I don't have time to go snooping  
in other people's jobs.

> Why not release public testing packages and then release real  
> upgrades after a short period? Maybe that would be an advantage in  
> competition too.

Who's going to test these?  Corporate customers who rely on high  
uptime for their servers and who *want* stability?  Even so, because  
the updates aren't on public mirrors, this is another channel that  
needs to be established for people to test.  Then there's  
coordination, reporting, fixing broken packages, enhancing things  
based on feedback, etc.  My, that sounds a lot like cooker.  =)

-- 
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C  A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig (application/pgp-signature, 186 B) - not displayed