#762781 security-tracker: Provide list of candidates for dsa-needed.txt/dla-needed.txt

#762781#5
Date:
2014-09-25 06:58:23 UTC
From:
To:
It would be nice if the security tracker could provide by release a list
of packages with open vulnerabilities (i.e. neither unimportant nor tagged
as no-dsa) that are not yet listed in dsa-needed.txt/dla-needed.txt
depending on the case.

It would help triage issues where no formal decision has been taken yet
on whether a DSA/DLA is warranted.

#762781#10
Date:
2014-09-25 07:14:07 UTC
From:
To:
Hi Raphaël,

thanks for this description, sounds implementable ;-)


cheers,
	Holger

#762781#15
Date:
2014-09-26 15:38:09 UTC
From:
To:
Hi,

The annoying part is that the mapping of "release => file to use" changes
over time. There's a one year period where oldstable is the realm of the
security team and only afterwards it gets into dla-needed.txt.

I wish we could use a unified process. After all dsa-needed.txt already
accepts "package/stable" and "package/oldstable" for the period where the
security team takes care of both. Maybe we could just always use that
scheme...

Cheers,

#762781#20
Date:
2014-09-27 10:40:03 UTC
From:
To:
Hi,

in the last month or so I came to realise that "the Debian security team
doesnt support LTS as a team, only by individual members" is not really true /
accurate. Or to phrase it differently and more positivly: I thankfully still
see many edits to data/CVE/list which refer to squeeze too! Thats awesome!

So I think LTS has put a little bit more work on the security teams shoulders.
And we should acknowledge / not forget that. (Which I think we do best by
working with them, roughly like we have done so far :)


cheers,
	Holger

#762781#25
Date:
2014-09-28 08:16:46 UTC
From:
To:
But that happens only every two years and for every release we need to make
some minor tweaks anyway.

Let's use the current process for some time and re-evaluate later.

Cheers,
        Moritz