Gentoo Archives: gentoo-dev

From: Karsten Schulz <kaschu@×××××××××.de>
To: gentoo-dev@g.o
Subject: Re: [gentoo-dev] GLEP #14: security updates based on GLSA
Date: Sat, 23 Aug 2003 12:02:21
Message-Id: 200308231402.20336.kaschu@t800.ping.de
In Reply to: Re: [gentoo-dev] GLEP #14: security updates based on GLSA by Marius Mauch
1 Am Samstag, 23. August 2003 07:58 schrieb Marius Mauch:
2 > Well, I've taken that from the existing GLSA format, it is currently
3 > not used by my code. I've no real opinion on that, someone from the
4 > security team (aliz, solar ?) should decide that.
5
6 I would really like to hear from the security people what they think.
7
8 > > communication works (Who creates and checks GLSAs, which public
9 > > keys are used, a.s.o.)
10 >
11 > Well, I think that's outside of the scope of this GLEP.
12
13 ack.
14
15 > I don't like the idea of GLSAs being used for that, a simple status
16 > update email on gentoo-security should do the job (again, that's
17 > outside the scope of this GLEP).
18
19 As I understand GLSAs (Gentoo Linux Security Announcements), they should
20 be used to announce security related information. I cannot find a
21 source, where they are defined to deliver fixes in any case. Again, we
22 need information from the Gentoo security experts to make this point
23 clear, I think.
24
25 > The DTD does not require the <fixed> tag to contain a <version> tag,
26 > so the special value none is not necessary.
27
28 ok, I see!
29
30 Karsten
31
32
33
34 --
35 gentoo-dev@g.o mailing list