Ian P. Christian wrote:
> On 08/16/06 Paul Kölle wrote:
>> The basic problem here is: Upstream may not publish "security fixes"
>> but just a new (fixed) version. If you want a "stable" tree, you have
>> to watch upstream cvs/svn/mailing lists and backport fixes. That is a
>> lot of work.
>
> that infrastructure is already in place in gentoo. Package maintainers
> do it... they need to just make it clear when they update an ebuild
> weather it's a general upgrade, or a security upgrade.
glsa-check will tell you if it's a security upgrade, but it will do
version bumps including ${PV} nevertheless. That is, your dependency
tree will change and possibly lead to unwanted upgrades (read: upgrade
with possible config changes, new features, new bugs).
AFAIK gentoo devs don't do backports, i.e. if samba has a vulnerability
in say 3.0.23a which is fixed in 3.0.23b, you won't get a "security
fixes only" 3.0.23a-r1 but just 3.0.23b with new features *and* fixed bugs.
cheers
Paul
--
[email protected] mailing list