Gentoo Archives: gentoo-dev

From: Tom Wijsman <TomWij@g.o>
To: gentoo-dev@l.g.o
Cc: pinkbyte@g.o
Subject: Re: [gentoo-dev] rfc: stabilization policies
Date: Wed, 21 Aug 2013 09:16:35
Message-Id: 20130821111628.37fffc3d@TOMWIJ-GENTOO
In Reply to: Re: [gentoo-dev] rfc: stabilization policies by Sergey Popov
1 On Wed, 21 Aug 2013 12:21:41 +0400
2 Sergey Popov <pinkbyte@g.o> wrote:
3
4 > 21.08.2013 12:17, Tom Wijsman пишет:
5 > > On Wed, 21 Aug 2013 11:57:22 +0400
6 > > Sergey Popov <pinkbyte@g.o> wrote:
7 > >
8 > >> 20.08.2013 23:42, Tom Wijsman пишет:
9 > >>> On Tue, 20 Aug 2013 14:29:09 -0400
10 > >>> Wyatt Epp <wyatt.epp@×××××.com> wrote:
11 > >>>> What manner of bitrot?
12 > >>>
13 > >>> They might ...
14 > >>>
15 > >>> 2. ... contain security bugs that later versions have fixed.
16 > >>
17 > >> There should be security bug on our bugzilla with quick
18 > >> stabilization on it and(probably) GLSA.
19 > >
20 > > Not all security bugs are visible; the older a piece of software,
21 > > the higher the chance that some people know about one or another
22 > > exploit that the rest of the world does not know about.
23 > >
24 >
25 > True. But blindly bringing new versions into stable(without testing)
26 > cause it POSSIBLY(without ChangeLog notes or CVES or whatever)
27 > contains LESS security problems is not an option. Stable should be
28 > reasonable
29
30 That's not what I am suggesting.
31
32 It is not about bringing in new versions, but about getting rid of
33 OLD versions which LIKELY contain MORE security problems than you
34 imagine. Keeping them around for too long time isn't reasonable...
35
36 --
37 With kind regards,
38
39 Tom Wijsman (TomWij)
40 Gentoo Developer
41
42 E-mail address : TomWij@g.o
43 GPG Public Key : 6D34E57D
44 GPG Fingerprint : C165 AF18 AB4C 400B C3D2 ABF0 95B2 1FCD 6D34 E57D

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-dev] rfc: stabilization policies Pacho Ramos <pacho@g.o>