Gentoo Archives: gentoo-dev

From: Sune Kloppenborg Jeppesen <jaervosz@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Determining ebuild stability and the 30 day suggestion
Date: Tue, 19 Jun 2007 21:09:14
Message-Id: 200706192305.14985.jaervosz@gentoo.org
In Reply to: Re: [gentoo-dev] Determining ebuild stability and the 30 day suggestion by Luis Francisco Araujo
1 On Tuesday 19 June 2007 06:40, Luis Francisco Araujo wrote:
2 > I use to ask for stabilization of the new version of a package
3 > immediately if it is supposed to fix an *important* security problem in
4 > the package, so that way we spread as soon as possible the new fix to
5 > our users.
6 >
7 > Not sure if this is documented somewhere as an exception to the 30 days
8 > rule, but i have not had problems so far and the stabilization teams
9 > have been willing to help me in such a cases.
10
11 We (the security team) ask for stabilization sooner than 30 days according to
12 our policy¹. AFAIR it has only resulted in a few glitches now and then. When
13 they happen they should be assigned to us to fix any regression.
14
15 ¹ http://www.gentoo.org/security/en/vulnerability-policy.xml
16 --
17 Sune Kloppenborg Jeppesen
18 Gentoo Linux Security Team
19 --
20 gentoo-dev@g.o mailing list