Hi,

On Wed, Aug 12, 2026 at 11:11:13AM +0200, Piotr Smyrak wrote:
> > This is not really the way to address CVE alert fatigue for people
> > that do not want to hack around the alerting system by building their
> > own stuff left and right.
> 
> Of course. And I agree with you. Still this is a voluntary free software
> project. So despite patches being welcome, they may not come ready
> tomorrow. 

I understand.  Just trying to bring other perspectives to the table.

(While I do understand "ports" and "vuxml" halfway by now, I'm not sure
I understand the FreeBSD shell script magic sufficiently to contribute
here)

[..]
> In test reporting there is a concept of an expected fail, or
> acknowledged one, and certain monitoring systems allow for flipping
> such forever failing test item into green by marking it as such. Which
> may as well in future turn red when it stops failing and thus then
> needs to be turned around again. 
> 
> What I am trying to say above is that the approach may also depend on
> what monitoring tool one uses.

"daily mail with security and pkg audit included"...
(daily_status_security_pkgaudit_enable=YES)

gert

-- 
"If was one thing all people took for granted, was conviction that if you 
 feed honest figures into a computer, honest figures come out. Never doubted 
 it myself till I met a computer with a sense of humor."
                             Robert A. Heinlein, The Moon is a Harsh Mistress

Gert Doering - Munich, Germany                             [email protected]

Reply via email to