[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Bits from the Security Team (for those that care about bits)



Thijs Kinkhorst <thijs@debian.org> writes:

> * Issues in specific packages
>
> We further discussed some specific problematic packages. One example is
> ia32-libs, which is difficult because it includes 100+ other source
> packages. This will be handled better for Squeeze: we'll have to ensure
> it's as up to date as possible at time of release, and will keep
> updating it in stable point updates to include newer package versions
> from the security archive (or the stable release itself).

A while back I looked into making the detection of security bugs in
ia32-libs (which is all just code duplication of other packages)
automatic. But the config for that detection would have needed 100+
config entries, which would ahve become verry ugly to maintain.

Has there been any change for this?

MfG
        Goswin


Reply to: