Re: Guidance on no-dsa and adding entries to dsa/dla-needed.txt

2014-09-24 Thread Holger Levsen
Hi, On Dienstag, 23. September 2014, Michael Gilbert wrote: There is a page that lists candidates for DTSA (Debian Testing Security Announcements), which aren't actually done anymore I can remove it, if it's really not used at all anymore. , but something like that would be very useful for

Re: Guidance on no-dsa and adding entries to dsa/dla-needed.txt

2014-09-24 Thread Salvatore Bonaccorso
Hi all, On Wed, Sep 24, 2014 at 02:37:00PM +0200, Holger Levsen wrote: [...] Then the separate text files could go away, and we can just use no-dsa in the CVE list to keep those pages up to date. you mean those dsa-needed.txt and dla-needed.txt files? We could. But right now we also use

Guidance on no-dsa and adding entries to dsa/dla-needed.txt

2014-09-22 Thread Raphael Hertzog
Hello, I'm in the process of reviewing open CVE in oldstable and deciding whether it must be added to dla-needed.txt or not. I have multiple questions: 1/ is there a page on the security tracker that lists packages with open vulnerabilities in stable/oldstable which are neither unimportant, nor

Re: Guidance on no-dsa and adding entries to dsa/dla-needed.txt

2014-09-22 Thread Holger Levsen
Hi Raphael, thanks for your work on triaging oldstable related CVEs! On Montag, 22. September 2014, Raphael Hertzog wrote: 1/ is there a page on the security tracker that lists packages with open vulnerabilities in stable/oldstable which are neither unimportant, nor marked no-dsa and not