Gentoo Archives: gentoo-user

From: Alan McKinnon <alan.mckinnon@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Alternatives to GLSA?
Date: Sat, 17 Sep 2011 13:14:15
Message-Id: 20110917151302.39373d6f@rohan.example.com
In Reply to: [gentoo-user] Alternatives to GLSA? by Florian Philipp
1 On Sat, 17 Sep 2011 11:17:56 +0200
2 Florian Philipp <lists@×××××××××××.net> wrote:
3
4 > Hi list!
5 >
6 > Since GLSAs are in their current state of disregard, I'm searching for
7 > another way to be informed about security fixes. What do you think is
8 > the best approach here?
9 >
10 > Querying bugzilla for recently fixed security bugs like [1]?
11 >
12 > Searching for the term 'security bug' or something similar in
13 > Changelogs?
14 >
15 > Looking at some other web site or distribution and anticipate changes
16 > in in the portage tree?
17 >
18 > [1]
19 > https://bugs.gentoo.org/buglist.cgi?list_id=428229;query_format=advanced;chfield=bug_status;chfieldfrom=2011-06-01;chfieldto=Now;chfieldvalue=RESOLVED;component=Security
20
21 If you just want to be informed out the state of security of packages,
22 subscribe to the security lists of other distros. I find RedHat and
23 Fedora to be useful and up to date. If you see something that looks
24 like you need to take action, find the corresponding Gentoo package and
25 investigate further.
26
27 If you need to be on the cutting edge of security issues, then you need
28 to be on the various vuln disclosure lists around. But be warned, they
29 can be noisy and you have to train your brain in what to ignore
30
31
32 --
33 Alan McKinnnon
34 alan.mckinnon@×××××.com

Replies

Subject Author
Re: [gentoo-user] Alternatives to GLSA? Florian Philipp <lists@×××××××××××.net>