1 |
10.01.2014 19:02, Sascha Wolf пишет: |
2 |
> Hi, |
3 |
> |
4 |
> I find the new version of GLSA format very interesting, especially |
5 |
> with the backdrop of the automated evaluation of vulnerabilities. |
6 |
> |
7 |
> Would it be possible to specify in which branch of Gentoo, this |
8 |
> program is usually installed? For example, "stable" or "unstable"? |
9 |
> |
10 |
> So you can better see if you are actively involved or not. |
11 |
> |
12 |
|
13 |
Current workflow will not be changed: |
14 |
|
15 |
- for packages, having stable versions - new versions will be |
16 |
stabilized, vulnerable versions - removed from tree. GLSA will be |
17 |
released if it's necessary, AFTER stabilization will be finished for all |
18 |
security supported arches. |
19 |
- for packages, that never was in stable - GLSA will NOT be even drafted. |
20 |
|
21 |
One notable exception for 1) - we do not do GLSAs for kernel packages. |
22 |
|
23 |
So, to conclude, we track all vulnerabilities, that are discovered in |
24 |
main portage tree, but GLSAs mainly targeted for stable systems, e.g. |
25 |
stable branch should not contain vulnerable software(ideally). |
26 |
|
27 |
-- |
28 |
Best regards, Sergey Popov |
29 |
Gentoo developer |
30 |
Gentoo Desktop Effects project lead |
31 |
Gentoo Qt project lead |
32 |
Gentoo Proxy maintainers project lead |