From 1be510f9529cb082f802408b472a77d074b394c0 Mon Sep 17 00:00:00 2001 From: Nicolas Vigier Date: Sun, 14 Apr 2013 13:46:12 +0000 Subject: Add zarb MLs html archives --- zarb-ml/mageia-dev/20110416/004014.html | 79 +++++++++++++++++++++++++++++++++ 1 file changed, 79 insertions(+) create mode 100644 zarb-ml/mageia-dev/20110416/004014.html (limited to 'zarb-ml/mageia-dev/20110416/004014.html') diff --git a/zarb-ml/mageia-dev/20110416/004014.html b/zarb-ml/mageia-dev/20110416/004014.html new file mode 100644 index 000000000..75fabcd3d --- /dev/null +++ b/zarb-ml/mageia-dev/20110416/004014.html @@ -0,0 +1,79 @@ + + + + [Mageia-dev] Meeting for secteam start + + + + + + + + + +

[Mageia-dev] Meeting for secteam start

+ nicolas vigier + boklm at mars-attacks.org +
+ Sat Apr 16 22:04:40 CEST 2011 +

+
+ +
On Sat, 16 Apr 2011, Michael Scherer wrote:
+
+>
+>> Old Process:
+>>
+>> * monitor vendor-sec, discuss vulns, patches, negotiate release schedule,
+>>    also watch other distro updates, for things we may have missed
+>
+> We could ask to maintainers to help on that regard,
+> or, like proposed for mageia-app-db and package testing, have a list of 
+> people
+> dedicated on gathering such informations. For example, someone say "I take
+> care of watching security for libreoffice and will warn secteam if
+> something need to be done".
+
+We can maybe also use the "Open Source Vulnerability Database" from
+http://osvdb.org/. This database can be downloaded, so maybe we can
+integrate it into youri-check.
+
+I think it will requires some work to match software name in OSVD and
+our package names. Some people created "distromatch", a tool to match
+package names between distributions. Maybe OSVD could be added to
+distromatch.
+
+
+ + +
+

+ +
+More information about the Mageia-dev +mailing list
+ -- cgit v1.2.1