1 |
On Wed, 21 Aug 2013 12:21:41 +0400 |
2 |
Sergey Popov <pinkbyte@g.o> wrote: |
3 |
|
4 |
> 21.08.2013 12:17, Tom Wijsman пишет: |
5 |
> > On Wed, 21 Aug 2013 11:57:22 +0400 |
6 |
> > Sergey Popov <pinkbyte@g.o> wrote: |
7 |
> > |
8 |
> >> 20.08.2013 23:42, Tom Wijsman пишет: |
9 |
> >>> On Tue, 20 Aug 2013 14:29:09 -0400 |
10 |
> >>> Wyatt Epp <wyatt.epp@×××××.com> wrote: |
11 |
> >>>> What manner of bitrot? |
12 |
> >>> |
13 |
> >>> They might ... |
14 |
> >>> |
15 |
> >>> 2. ... contain security bugs that later versions have fixed. |
16 |
> >> |
17 |
> >> There should be security bug on our bugzilla with quick |
18 |
> >> stabilization on it and(probably) GLSA. |
19 |
> > |
20 |
> > Not all security bugs are visible; the older a piece of software, |
21 |
> > the higher the chance that some people know about one or another |
22 |
> > exploit that the rest of the world does not know about. |
23 |
> > |
24 |
> |
25 |
> True. But blindly bringing new versions into stable(without testing) |
26 |
> cause it POSSIBLY(without ChangeLog notes or CVES or whatever) |
27 |
> contains LESS security problems is not an option. Stable should be |
28 |
> reasonable |
29 |
|
30 |
That's not what I am suggesting. |
31 |
|
32 |
It is not about bringing in new versions, but about getting rid of |
33 |
OLD versions which LIKELY contain MORE security problems than you |
34 |
imagine. Keeping them around for too long time isn't reasonable... |
35 |
|
36 |
-- |
37 |
With kind regards, |
38 |
|
39 |
Tom Wijsman (TomWij) |
40 |
Gentoo Developer |
41 |
|
42 |
E-mail address : TomWij@g.o |
43 |
GPG Public Key : 6D34E57D |
44 |
GPG Fingerprint : C165 AF18 AB4C 400B C3D2 ABF0 95B2 1FCD 6D34 E57D |