Re: Ubuntu Migration
[email protected] (David D. Smith)
| Newsgroups | gmane.org.user-groups.linux.morlug |
|---|---|
| Organization | Only myself |
| Message-ID | <[email protected]> |
"Michael" == Michael Bond <[email protected]> writes: Michael> Now, i'm sure every effort goes into making sure the Michael> packages are stable .. but what if there is a major Michael> security update to a package ... for example, zlib. The Michael> user has to update all their programs that use it with the Michael> current unstable ... With dpkg-based apt, at least, that’s not how it works. The vast majority of package dependencies are on minimum version numbers, so if a flaw is exposed in zlib and you have an old version, installing a higher version number won’t violate any of those older dependencies. Now, if you’re referring to a security vulnerability found after an ABI change, the security team is supposed to backport that fix into the older version of the library and push it out through the security updates repository. If MEPIS is using apt with default package pinning to only use packages from a more bleeding-edge distribution when necessary to satisfy dependencies, this shouldn’t ever be a problem. The APT-HOWTO does a really bad job the last time I checked regarding how to set this up, so I’ve attached my /etc/apt/preferences file to show an example and with this and the APT-HOWTO, you should see exactly what I mean. Cheers, -- David D. Smith A man without doubt is a monster. _______________________________________________ Morlug mailing list [email protected] http://mailman.morlug.org/mailman/listinfo/morlug
preferences
(application/octet-stream, 186 B) - not displayed
signature.asc
(application/pgp-signature, 188 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQBCByP1EJGOueZRHH4RArtSAJ4pTNH8xY4qykwiuPNRXaboW5f40gCeIx9z YNDF5WQnvLTrqETj0/aY/Os= =nIxY -----END PGP SIGNATURE-----