On Fri, Sep 26, 2014, at 10:25, Paul Hoffman wrote:
> 
> I appreciate the speed that folks update the packages; I'm a bit
> distressed that 9.3 seems to be a second-class citizen for security
> fixes. (And I totally admit that I could be misreading the situation.)
> 

(speaking strictly as a consumer of the pkg repository)

I am not aware of any other packages with security vulnerabilities that
have been updated on the repository outside of the planned once-a-week
schedule. This means if the package set is built and published and
immediately thereafter a vulnerability comes out for www/chromium, don't
expect to see the update until next week.

There is a desire to solve this problem and it is not simple solution.
Keep in mind that the ports tree existed for 20 years now expecting
people to consume it from source, not from packages. I've witnessed the
ports team and ports-mgmt/pkg authors perform miracles over the last 2
years and they have further plans to modernize the architecture.

FYI, the repositories are built sequentially and I don't think there's a
preference of a certain release over another. They're working hard to
get these updated packages out the door as fast as possible.
_______________________________________________
freebsd-security@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscr...@freebsd.org"

Reply via email to