Gentoo Archives: gentoo-dev

From: Brian Evans <grknight@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] qa last rites multiple packages
Date: Wed, 07 Jan 2015 13:37:24
Message-Id: 54AD368B.1070007@gentoo.org
In Reply to: [gentoo-dev] qa last rites multiple packages by William Hubbs
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 On 1/6/2015 6:47 PM, William Hubbs wrote:
5 > All,
6 >
7 > these packages have been masked in the tree for months - years with
8 > no signs of fixes.
9 >
10 > I am particularly concerned about packages with known security
11 > vulnerabilities staying in the main tree masked. If people want to
12 > keep using those packages, I don't want to stop them, but packages
13 > like this should not be in the main tree.
14
15 > # Sergey Popov <pinkbyte@g.o> (04 Sep 2014) # Security mask,
16 > wrt bugs #488212, #498164, #500260, # #507802 and #518718
17 > <virtual/mysql-5.5 <dev-db/mysql-5.5.39 <dev-db/mariadb-5.5.39
18 >
19
20 The mysql team keeps old upgrades around for several months on purpose
21 to give admins time to migrate between major/minor releases.
22
23 Thanks for the reminder to cleanup. It is time to do so.
24
25 Brian Evans
26 -----BEGIN PGP SIGNATURE-----
27 Version: GnuPG v2.0.17 (MingW32)
28
29 iQEcBAEBAgAGBQJUrTaLAAoJEE4V4vFnx44dEQ0H/1gNWrI6DUPRKwrxnlwCjlrW
30 gVOS6p2LGVCxOx+qm98bvTYpt3HD3N4HB8IXnJRiPrOpQ/AW8VpyF+gQCN7jVsVP
31 vW1C/peuusERVvGfbIW8j86xl3ZQc3R8RDBlxRR11nxXRhrM5Bb8gpNWpHq5ni3R
32 zb6nT1+jYZ7Ix/UNWB2tnVW/H5Q/bBujVyjYrc94XKuEuHZORmS7/q+gD4oFF8+Q
33 B/TtK7ouJ+G8CX3WjM8pXRrg7mPukTQFgOEqZsZ8tqVyqGaE/KmR+jrFlVbrLMuD
34 xZvIkpvFUYwf/mdToUd1QNBblRdFs0wvGK06vkUDKJDJjz/mWhyWlVzJQQFjr2s=
35 =95aa
36 -----END PGP SIGNATURE-----