Gentoo Logo
Gentoo Spaceship

Installation:
Gentoo Handbook
Installation Docs

Documentation:
Home
Listing
About Gentoo
Philosophy
Social Contract

Resources:
Bug Tracker
Developer List
Discussion Forums
Gentoo BitTorrents
Gentoo Linux Enhancement Proposals
IRC Channels
Mailing Lists
Mirrors
Name and Logo Guidelines
Online Package Database
Security Announcements
Staffing Needs
Supporting Vendors
View our CVS

Graphics:
Logos and themes
Icons
ScreenShots

Miscellaneous Resources:
Gentoo Linux Store
Gentoo-hosted projects
IBM dW/Intel article archive




List Archive: gentoo-dev
Navigation:
Lists: gentoo-dev: < Prev By Thread Next > < Prev By Date Next >
Headers:
To: gentoo-dev@g.o
From: Jan Kundrát <jkt@g.o>
Subject: Re: EAPI 2 policy for portage tree
Date: Tue, 09 Dec 2008 17:57:21 +0100
Jean-Marc Hengen wrote:
> tree and my policies (more precisely: I can't keep current stable 
> portage and cmake-2.6.2). My solution to the problem, was to copy the 
> ebuild in /var/db/pkg to my local overlay and I'm fine with it for now. 
> The drawback of this workaround is, I could miss important fixes, like 
> security fixes.

[snip]

> the cmake-2.6.2 ebuild. This has the advantage, that people with a setup 
> like mine can continue to use, what they already use and work on the 
> cmake ebuild can continue in the new revision. If the new revision fixes 
> a security issue, one can mask the old version, with a message with bug 
> telling this.

Just FYI, there's no difference -- when you've chosen to use the ~arch 
version, you *have* to follow any updates to it as soon as possible if 
you want to be reasonably sure you aren't affected by a security bug, as 
our security team doesn't issue GLSAs for ~arch packages. Sticking with 
a version that works for you doesn't mean you're somehow protected form 
security bugs.

So to put this into perspective with cmake -- if there was a security 
bug in current version (which you'd keep as you don't want to upgrade 
Portage) and the fix for this bug would be using EAPI=2 (which is not an 
unrealistic situation), you'd be affected.

Cheers,
-jkt

-- 
cd /local/pub && more beer > /dev/mouth

Attachment:
signature.asc (OpenPGP digital signature)
References:
EAPI 2 policy for portage tree
-- Jean-Marc Hengen
Navigation:
Lists: gentoo-dev: < Prev By Thread Next > < Prev By Date Next >
Previous by thread:
Re: EAPI 2 policy for portage tree
Next by thread:
Proposal: add a compiler-version entry to pkg db
Previous by date:
Re: Proposal: disable python and perl USE flags in profile
Next by date:
Re: Proposal: add a compiler-version entry to pkg db


Updated Jun 17, 2009

Donate to support our development efforts.

Gentoo Centric Hosting: vr.org

VR Hosted

Tek Alchemy

Tek Alchemy

SevenL.net

SevenL.net

php|architect

php|architect

Copyright 2001-2007 Gentoo Foundation, Inc. Questions, Comments? Email www@gentoo.org.