Re: Maintaining kernel source in sarge

On Mon, May 26, 2003 at 10:00:06PM +0200, Yann Dirson wrote:
> We could get around Guido's point mentionned above by having a list of
> default patches to apply, which would by default contain the debian
> patch.

Yes, but then the problem is that unsuspecting users could be
building kernels using the kernel-source package thinking that
it contained all the security fixes.

I believe that distributing a binary package that may contain
known security problems is a very serious problem.
