Re: Translator Release for /cvsroot/fink/web/xml/security/sec-policy.en.xml

Michèle Garoche <[email protected]>
Newsgroups gmane.os.apple.fink.i18n
Message-ID <[email protected]>
Hi David,

The French translation is ready, not added though, since adding it may 
lead to an unfortunate activation later, while translating other 
documents.

Apart some misspelling and wrong punctuation, I have noted two things 
that are not perfectly clear to me:

1 - in preface

... Fink recognizes the necessity to offer a uniform policy

offer seems to me a mild word as this is an enforcement. Maybe: to put 
in place a.... that every maintainer should follow be it the case.

2 - The location of the maintainer's email address is stated twice in a 
row in section who is responsible and whom shall I contact, maybe one 
is sufficient, as both sections are below one another.

3 - The maintainer's role is not clear to me. Say the user notifies 
both the maintainer and Fink Core, the maintainer acknowledges the 
notification, then what should he do? Nothing, just sitting awaiting 
that the Fink Core Team answers? That's what appears to me when reading 
section pre-notifications, unless I'm missing something obvious.

4 - Should not the remote DOS exploit be presented before the local 
root exploit in section response time as its response time is shorter? 
The same for remote data corruption. I mean it seems more logical to 
present them in order of responsiveness than in order of type of 
security issues, as the the whole paragraph is about response time.

5 - The section forced update seems to contradict the section 
pre-notifications from the point of view of the maintainer's role. 
Here, he is supposed to take action. Which ones? (as he is not supposed 
to answer according to pre-notification section).

6 - What the user should do when he discovers a security incident, but 
it is not yet reported in the official sources? Not clear from section 
acceptable incident sources.

7 - What happens when none of the conditions stated on section security 
update procedure are met? Does the package remains as is in Fink?

8 - Section unstable to stable moves: it is stated that the package 
info file is moved to stable. It can be also that there is a patch 
file.

9 - While it is good that the Fink announcement list be used, is that 
certain that many users read it? (section sending notifications). 
Should not a notification be sent to beginners and users mailing lists 
as soon as the correction are made, to ensure that most users see it?

10 - Template
Should the package's version be stated too?

Michèle
<http://micmacfr.homeunix.org>
PGP.sig (application/pgp-signature, 186 B) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.