[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Potential expoits via application launchers (aka .desktop files)



Hi,

On Donnerstag, 12. Februar 2009, Michael S. Gilbert wrote:
> I'll wait for lenny to
> get out the door rather than submitting these apparently complex and
> difficult security (and hence release-critical) issues at the last
> minute.

Please dont hesitate to file bugs (unless the issue at hand is security 
related and not public yet, which is not the case here).

While it's true that Debian tries to release with 0 RC bugs, it's not the case 
that a planned release is stopped, "just because" a bug with severity serious 
or higher pops up. (Because certain bugs can be ignored. If lenny were 
released today and a RC bug pops up tomorrow, we wont pull back the release 
neither.)

It's also much better to ship with a known and reported bug, than to ship with 
a bug, which is not reported :) (Because of "we wont hide problems" and 
because it's generally better to be aware of problems than not.)


regards,
	Holger

Attachment: signature.asc
Description: This is a digitally signed message part.


Reply to: