[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: tracker CVE feed source



	Hi! :)

* Nico Golde <nico@ngolde.de> [2008-08-04 21:01:18 CEST]:
> * Thijs Kinkhorst <thijs@debian.org> [2008-08-04 20:16]:
> > We have the following options:
> > - Keep the current feed.
> >   It works. But, it's only updated a few times a week, but this may get more
> >   often in the future.
> 
> While I agree that this may be bad because we get some of 
> the vulnerabilities later I also see a good thing in this. 
> This way we don't have to work on this every day but are 
> able to work on bigger chunks every now and then which may 
> be better unless we have more active people working on new 
> CVE ids.

 I don't follow that reasoning. Even if the stuff gets in more timely it
doesn't mean that they would have to get processed more timely than they
are processed currently. If you feel like working on bigger chunks feel
free to let it pile up like it's done through the way it's received. I
see much bigger advantages with changing it than what might be
considered a good thing in this...

 About directly feeding the mails in, how many commits a day are we
speaking here?

 So long, :)
Rhonda


Reply to: