Re: "Recommended" status of Leap update openSUSE-2020-1390
Marcus Meissner <[email protected]> Sun, 13 Sep 2020 09:14:41 +0200
| Newsgroups | gmane.linux.suse.security |
|---|---|
| Organization | SUSE Software Solutions Ger many GmbH, Maxfeldstr. 5, 90409 Nuernberg, Germany , GF: Felix Imendörffer, HRB 36809, AG Nürnber g |
| Message-ID | <[email protected]> |
On Sat, Sep 12, 2020 at 10:06:23PM +0300, Alexander Shchadilov wrote: > Hello, > openSUSE-2020-1390 patch for "libmediainfo" and "mediainfo" fixes some > CVE issue but is classified as "recommended" and not as "security". > https://bugzilla.suse.com/show_bug.cgi?id=1173630 > https://lists.opensuse.org/opensuse-updates/2020-09/msg00077.html > > Does this mean that "security" status is restricted to updates that > modify critical software from some closed list (a list of packages > that is tracked by the security team)? We depend a bit on the packagers also mentioning the CVE in their changes entries (and not just this line: - Add libmediainfo-MpegPs.patch (fixes boo#1173630) ) As it was not correctly submitted (without CVE in changes entry) I missed this while processing it. So if you have a CVE, please always also add it to the .changes entry, our automation then automatically marks it as security. Ciao, Marcus -- To unsubscribe, e-mail: [email protected] To contact the owner, e-mail: [email protected]