From 1be510f9529cb082f802408b472a77d074b394c0 Mon Sep 17 00:00:00 2001 From: Nicolas Vigier Date: Sun, 14 Apr 2013 13:46:12 +0000 Subject: Add zarb MLs html archives --- zarb-ml/mageia-dev/2011-June/006110.html | 121 +++++++++++++++++++++++++++++++ 1 file changed, 121 insertions(+) create mode 100644 zarb-ml/mageia-dev/2011-June/006110.html (limited to 'zarb-ml/mageia-dev/2011-June/006110.html') diff --git a/zarb-ml/mageia-dev/2011-June/006110.html b/zarb-ml/mageia-dev/2011-June/006110.html new file mode 100644 index 000000000..6bf83bd39 --- /dev/null +++ b/zarb-ml/mageia-dev/2011-June/006110.html @@ -0,0 +1,121 @@ + + + + [Mageia-dev] Mageia Advisories Database + + + + + + + + + +

[Mageia-dev] Mageia Advisories Database

+ nicolas vigier + boklm at mars-attacks.org +
+ Tue Jun 28 17:58:20 CEST 2011 +

+
+ +
On Tue, 28 Jun 2011, Michael Scherer wrote:
+
+> Le mardi 28 juin 2011 à 16:23 +0200, Christiaan Welvaart a écrit :
+> > On Tue, 28 Jun 2011, nicolas vigier wrote:
+> > 
+> > > In order to send updates advisories, and have a web page listing all
+> > > previous advisories, we need to create a database to store them.
+> > >
+> > > So I think it should have the following info for each advisory :
+> > >
+> > > - advisory ID: something like MGA-[NUMBER] ?
+> > > - advisory date
+> > > - affected source packages
+> > > - affected distribution versions
+> > > - CVE numbers
+> > > - list of binary packages with sha1sum
+> Is there people that really check them ?
+> ( since there is already gpg and checksum in rpm that can be checked
+> automatically, I do not see the point in having this when it requires
+> another manual check )
+
+Most other distributions include this in their advisories. But yes, it's
+not very useful, so we can probably remove the sha1.
+
+> 
+> > > - Mageia Bug #
+> > > - Reference URLs
+> > > - advisory text
+> > >
+> > > Anything else ?
+> > 
+> > - severity
+> Adding severity would requires us to have precise rules about it, and
+> would not mean much, and likely lots of bike shedding about it.
+> 
+> And also, what is the use precisely ?
+> 
+> > - whether this is a security issue or a non-security bugfix
+> What if there is more than 1 fix ( like a firefox upgrade ) ?
+
+If at least one of them is security, then it's a security update.
+
+
+ + + + + + + + + + + + + + + + + + + + + + + + + + +
+

+ +
+More information about the Mageia-dev +mailing list
+ -- cgit v1.2.1