On Fri, Sep 26, 2014, at 10:25, Paul Hoffman wrote: > > I appreciate the speed that folks update the packages; I'm a bit > distressed that 9.3 seems to be a second-class citizen for security > fixes. (And I totally admit that I could be misreading the situation.) >
(speaking strictly as a consumer of the pkg repository) I am not aware of any other packages with security vulnerabilities that have been updated on the repository outside of the planned once-a-week schedule. This means if the package set is built and published and immediately thereafter a vulnerability comes out for www/chromium, don't expect to see the update until next week. There is a desire to solve this problem and it is not simple solution. Keep in mind that the ports tree existed for 20 years now expecting people to consume it from source, not from packages. I've witnessed the ports team and ports-mgmt/pkg authors perform miracles over the last 2 years and they have further plans to modernize the architecture. FYI, the repositories are built sequentially and I don't think there's a preference of a certain release over another. They're working hard to get these updated packages out the door as fast as possible. _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscr...@freebsd.org"