[Lvfs-announce] Update descriptions in components

Richard Hughes <[email protected]> Tue, 18 May 2021 19:39:43 +0100
Newsgroups dev.linux.lists.lvfs-announce
Message-ID <CAD2FfiHoXL5B83-cL+pu_5mv9pWQzw+V2SGEL6KSS6_xPJr5rg@mail.gmail.com>
Hi all,

I=E2=80=99ve just deployed a change to the LVFS that adds a requirement to =
the
update description of at least 10 =E2=80=9Cuseful=E2=80=9D words. A lot of =
the recent
feedback from real users has been that quite a few of the update
descriptions have been almost useless, and numerous independent
studies have shown that poor update descriptions greatly reduce the
number of users actually applying security updates. Some of the bad
descriptions reported by users were literally of the form:

* =E2=80=9CFixed security vulnerabilities=E2=80=9D
* =E2=80=9CFixes menu bug=E2=80=9D
* =E2=80=9CNone=E2=80=9D
* =E2=80=9CUpdated the Diagnostics module=E2=80=9D

None of these actually described what was fixed, or helped the user
decide whether or not to apply the update. The update description for
each firmware is being read by *thousands* of users and we need to do
a lot better now we're deploying to more than a million devices every
month. I think requiring 10 useful words (not including tokens like
=E2=80=9Cupdate=E2=80=9D, =E2=80=9Cfixes=E2=80=9D, =E2=80=9Cbug=E2=80=9D et=
c) is a very low bar and the very least we
should provide. Of course, providing longer descriptions than ten
words is better still. As a reminder you can use lists in markdown
format, and a single empty line will be treated as a paragraph break.

If anyone notices any detection failures please let me know, also
including a link to the relevant firmware on the LVFS.

Thanks,

Richard