1 |
On Sat, 17 Sep 2011 11:17:56 +0200 |
2 |
Florian Philipp <lists@×××××××××××.net> wrote: |
3 |
|
4 |
> Hi list! |
5 |
> |
6 |
> Since GLSAs are in their current state of disregard, I'm searching for |
7 |
> another way to be informed about security fixes. What do you think is |
8 |
> the best approach here? |
9 |
> |
10 |
> Querying bugzilla for recently fixed security bugs like [1]? |
11 |
> |
12 |
> Searching for the term 'security bug' or something similar in |
13 |
> Changelogs? |
14 |
> |
15 |
> Looking at some other web site or distribution and anticipate changes |
16 |
> in in the portage tree? |
17 |
> |
18 |
> [1] |
19 |
> https://bugs.gentoo.org/buglist.cgi?list_id=428229;query_format=advanced;chfield=bug_status;chfieldfrom=2011-06-01;chfieldto=Now;chfieldvalue=RESOLVED;component=Security |
20 |
|
21 |
If you just want to be informed out the state of security of packages, |
22 |
subscribe to the security lists of other distros. I find RedHat and |
23 |
Fedora to be useful and up to date. If you see something that looks |
24 |
like you need to take action, find the corresponding Gentoo package and |
25 |
investigate further. |
26 |
|
27 |
If you need to be on the cutting edge of security issues, then you need |
28 |
to be on the various vuln disclosure lists around. But be warned, they |
29 |
can be noisy and you have to train your brain in what to ignore |
30 |
|
31 |
|
32 |
-- |
33 |
Alan McKinnnon |
34 |
alan.mckinnon@×××××.com |