Ian P. Christian wrote:
> On 08/16/06 Paul Kölle wrote:
>> The basic problem here is: Upstream may not publish "security fixes" 
>> but just a new (fixed) version. If you want a "stable" tree, you have 
>> to watch upstream cvs/svn/mailing lists and backport fixes. That is a 
>> lot of work.
> 
> that infrastructure is already in place in gentoo. Package maintainers
> do it... they need to just make it clear when they update an ebuild
> weather it's a general upgrade, or a security upgrade.

glsa-check will tell you if it's a security upgrade, but it will do
version bumps including ${PV} nevertheless. That is, your dependency
tree will change and possibly lead to unwanted upgrades (read: upgrade
with possible config changes, new features, new bugs).
AFAIK gentoo devs don't do backports, i.e. if samba has a vulnerability
in say 3.0.23a which is fixed in 3.0.23b, you won't get a  "security
fixes only" 3.0.23a-r1 but just 3.0.23b with new features *and* fixed bugs.

cheers
 Paul
-- 
[email protected] mailing list

Reply via email to