1 |
On Wed, Jan 07, 2015 at 01:08:21PM -0600, William Hubbs wrote: |
2 |
> On Wed, Jan 07, 2015 at 01:29:15PM -0500, Mike Pagano wrote: |
3 |
> > On Wed, Jan 07, 2015 at 11:11:32AM -0600, William Hubbs wrote: |
4 |
> > > On Wed, Jan 07, 2015 at 11:21:56AM -0500, Mike Pagano wrote: |
5 |
> > > > On Tue, Jan 06, 2015 at 05:47:10PM -0600, William Hubbs wrote: |
6 |
> > > > > All, |
7 |
> > William, |
8 |
> > |
9 |
> > At what point do we not care about users who have not upgraded and will |
10 |
> > miss this security message? |
11 |
> |
12 |
> I would say that's more up to you as the maintainer, but put something |
13 |
> to the affect in the mask comment. |
14 |
> |
15 |
> # This mask will be removed <whenever> |
16 |
> |
17 |
> William |
18 |
> |
19 |
|
20 |
Fair enough. This question is to anyone that supports users and works on |
21 |
bugs. Especially the portage devs. At what point do you say to a user |
22 |
that their system is so old that they really need to upgrade? |
23 |
|
24 |
2 years, 1 year, < 1 year? Maybe that's a good thing to state in documentation. |
25 |
|
26 |
"For a fully supported and "reasonably secure as possible" Gentoo system, the |
27 |
distribution expects users to update at least X times a year. Notice of |
28 |
insecure or potentially harmful packages is not guaranteed one year after |
29 |
official notification." |
30 |
|
31 |
Mike |
32 |
|
33 |
|
34 |
-- |
35 |
Mike Pagano |
36 |
Gentoo Developer - Kernel Project |
37 |
Gentoo Sources - Lead |
38 |
E-Mail : mpagano@g.o |
39 |
GnuPG FP : EEE2 601D 0763 B60F 848C 9E14 3C33 C650 B576 E4E3 |
40 |
Public Key : http://pgp.mit.edu:11371/pks/lookup?search=0xB576E4E3&op=index |