[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Debian release management and security questions



Le 05/02/2020 à 16:34, Itzik Reuven a écrit :
Hello Debian maintainers,

I have a few questions regarding the debian project and I will be glad for some answers:

1. regarding the release management - from a quick scanning of the release I have noticed that are 6 release types:
jessie
jessie-security

no longer supported by Debian. Supported in the LTS project, maintained by another people than Debian, until the end of the year 2020.

stretch - security

the same, but supported more long time by the external team, funded by companies to do it

buster

current stable

bullseye

current testing

sid

unstable


I would like to ask what is the difference between each release (what actually each release means), can different releases may obtain the same version (i.e sid -7.4.1 and buster-7.4.1 is possible?)

No. The packages are newer in testing and sid than stable. Except Mozilla ones who are up-to-date in stable according to ESR policy of these packages. Or if you do pinning but to be done carefully. Or if the package has a backport (buster-backports)


2. stable vs. unstable suite- meaning and difference?

stable is the state of the distro without critical bugs in his global working. Only security updates will be done in it, and only critical bugs. Not mure. unstable is the development repo where packages arrive before testing and stable, stable is released each 2 years (or more) unstable is up-to-date all the time

3. regarding the security tracker (https://security-tracker.debian.org/tracker/ <https://security-tracker.debian.org/tracker/>) the different pages in tracker refers to different vulnerability types I will be glad to understand what each page refers to since I don't fully understand from the description.

4. is there one specific debian host that holds all debian packages? if not is there a debian host for debian packages that are listed in the security tracker?

I dont understand. Do you mean snapshot.debian.org?

Regards


Thank you!

--
	

*Itzik Reuven*

Data Analyst

    & Software Developer

+972-53-8203-727

www.WhiteSourceSoftware.com <https://www.whitesourcesoftware.com/>

Ariel Sharon 4, HaShahar Tower32Floor

Givatayim, Israel 5320047


*WhiteSource <http://www.whitesourcesoftware.com/> empowers businesses to develop better software *
*by harnessing the power of open source*
<https://www.facebook.com/whitesource/><https://twitter.com/WhiteSourceSoft><https://www.linkedin.com/company/2440656/>


Reply to: