Gentoo Archives: gentoo-dev

From: "Michał Górny" <mgorny@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] [RFC] A new GLSA schema
Date: Sat, 12 Nov 2022 05:09:56
Message-Id: 68c8ce8bf2bf90b239b63bb65935c2c3e91c7554.camel@gentoo.org
In Reply to: Re: [gentoo-dev] [RFC] A new GLSA schema by Gordon Pettey
1 On Fri, 2022-11-11 at 16:06 -0600, Gordon Pettey wrote:
2 > On Thu, Nov 10, 2022 at 6:27 PM John Helmert III <ajak@g.o> wrote:
3 >
4 > > On Thu, Nov 10, 2022 at 09:49:27PM +0100, Jonas Stein wrote:
5 > > > On 10/11/2022 03:27, John Helmert III wrote:
6 > > > > The first GLSA in glsa.git is GLSA-200310-03, the third GLSA of
7 > > > > October 2003. It used roughly the same format of the GLSAs we release
8 > > > > today, in 2022, making that format almost as old as me.
9 > > >
10 > > > IFF we change the format, we should not invent a new standard [1] but
11 > > > use existing one like CSAF [2]
12 > > >
13 > > > [1] https://imgs.xkcd.com/comics/standards.png
14 > > > [2] https://oasis-open.github.io/csaf-documentation/
15 > >
16 > > We're not inventing a new "standard", we're upgrading the format we use
17 > > to distribute GLSAs.
18 > >
19 >
20 > Standard, format, semantics. You are producing a new schema in a field
21 > where at least one usable (and already-improved?) schema exists. NIH?
22
23 GLSA: 2003
24 CSAF: 2016
25
26 Sure sounds like OASIS did a NIH there.
27
28 --
29 Best regards,
30 Michał Górny