Gentoo Archives: gentoo-dev

From: John Helmert III <ajak@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] [RFC] A new GLSA schema
Date: Thu, 10 Nov 2022 04:19:33
Message-Id: Y2x7z3tsXxHKtH40@gentoo.org
In Reply to: Re: [gentoo-dev] [RFC] A new GLSA schema by Marc Schiffbauer
1 On Thu, Nov 10, 2022 at 02:10:09PM +1000, Marc Schiffbauer wrote:
2 > * Sam James schrieb am 10.11.22 um 13:58 Uhr:
3 > >
4 > > I think we'd rename impact -> description but description would now
5 > > be "description of the problem" and not "description of the package".
6 >
7 >
8 > +1, but additionally having the short description of the package sounds
9 > still useful to me, as not always everybody knows what any package is
10 > exactly for and the description will help a lot in telling the
11 > impact/danger of your own infra that might be caused by that package.
12 >
13 > -Marc
14
15 Are you saying you rely on the background field, which is generally
16 just the package's DESCRIPTION? Maybe glsa-check should just spit out
17 the package's DESCRIPTION then too.

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-dev] [RFC] A new GLSA schema Marc Schiffbauer <mschiff@g.o>