Gentoo Archives: gentoo-security

From: Sergey Popov <pinkbyte@g.o>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] Soliciting feedback for the GLSA-2 format
Date: Wed, 15 Jan 2014 11:14:53
Message-Id: 52D66D81.2090505@gentoo.org
In Reply to: [gentoo-security] Soliciting feedback for the GLSA-2 format by Sascha Wolf
1 10.01.2014 19:02, Sascha Wolf пишет:
2 > Hi,
3 >
4 > I find the new version of GLSA format very interesting, especially
5 > with the backdrop of the automated evaluation of vulnerabilities.
6 >
7 > Would it be possible to specify in which branch of Gentoo, this
8 > program is usually installed? For example, "stable" or "unstable"?
9 >
10 > So you can better see if you are actively involved or not.
11 >
12
13 Current workflow will not be changed:
14
15 - for packages, having stable versions - new versions will be
16 stabilized, vulnerable versions - removed from tree. GLSA will be
17 released if it's necessary, AFTER stabilization will be finished for all
18 security supported arches.
19 - for packages, that never was in stable - GLSA will NOT be even drafted.
20
21 One notable exception for 1) - we do not do GLSAs for kernel packages.
22
23 So, to conclude, we track all vulnerabilities, that are discovered in
24 main portage tree, but GLSAs mainly targeted for stable systems, e.g.
25 stable branch should not contain vulnerable software(ideally).
26
27 --
28 Best regards, Sergey Popov
29 Gentoo developer
30 Gentoo Desktop Effects project lead
31 Gentoo Qt project lead
32 Gentoo Proxy maintainers project lead

Attachments

File name MIME type
signature.asc application/pgp-signature