Re: Security tracker reports fixed issues in silc-toolkit
On Fri, 30 Oct 2009 18:41:57 +0100, Nico Golde wrote:
> Hi,
> * Jérémy Bobbio <lunar@debian.org> [2009-10-30 14:05]:
> > On Thu, Oct 29, 2009 at 05:39:35AM +0000, DDPOMail robot wrote:
> > > === silc-toolkit:
> > > = There are 6 unfixed security issue(s), please fix them.
> > > See http://security-tracker.debian.net/tracker/source-package/silc-toolkit
> >
> > All those issues have been fixed, but CVE were not referenced in the
> > Debian changelog (as the actual update made the security team register
> > new CVEs).
> >
> > Could you please update the security tracker regarding this issues?
>
> No. If you check the CVE ids in detail you will see that those issues are
> unfixed in oldstable, that's why the tracker shows it as open. If you look
> at http://security-tracker.debian.org/tracker/status/release/unstable you will
> see it doesn't show up there.
would it be useful to tag number of issues on a per release basis in the
pts to prevent future confusion in this regard? i.e. instead of
3 open issues in silc-toolkit
do
3 open issues in silc-toolkit in oldstable
0 open issues in silc-toolkit in stable
0 open issues in silc-toolkit in testing
0 open issues in silc-toolkit in unstable
mike
Reply to: