- Package:
- security-tracker
- Source:
- security-tracker
- Submitter:
- Raphaël Hertzog
- Date:
- 2014-09-28 08:21:04 UTC
- Severity:
- wishlist
It would be nice if the security tracker could provide by release a list of packages with open vulnerabilities (i.e. neither unimportant nor tagged as no-dsa) that are not yet listed in dsa-needed.txt/dla-needed.txt depending on the case. It would help triage issues where no formal decision has been taken yet on whether a DSA/DLA is warranted.
Hi Raphaël, thanks for this description, sounds implementable ;-) cheers, Holger
Hi, The annoying part is that the mapping of "release => file to use" changes over time. There's a one year period where oldstable is the realm of the security team and only afterwards it gets into dla-needed.txt. I wish we could use a unified process. After all dsa-needed.txt already accepts "package/stable" and "package/oldstable" for the period where the security team takes care of both. Maybe we could just always use that scheme... Cheers,
Hi, in the last month or so I came to realise that "the Debian security team doesnt support LTS as a team, only by individual members" is not really true / accurate. Or to phrase it differently and more positivly: I thankfully still see many edits to data/CVE/list which refer to squeeze too! Thats awesome! So I think LTS has put a little bit more work on the security teams shoulders. And we should acknowledge / not forget that. (Which I think we do best by working with them, roughly like we have done so far :) cheers, Holger
But that happens only every two years and for every release we need to make
some minor tweaks anyway.
Let's use the current process for some time and re-evaluate later.
Cheers,
Moritz