[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Security support incomplete? (was: Re: [SECURITY] [DSA 3455-1] curl security update)



Hi Wolfgang,

On Dienstag, 2. Februar 2016, Wolfgang Jeltsch wrote:
>   • Where does the tracker talk about security policies? (I actually
>     doubt that such information is in the tracker at all.)

That's out of scope for the tracker indeed, however right now I dont know 
where to find such policies.

>   • Where is a list of unfixed security issues?

https://security-tracker.debian.org/tracker/ links to filters for the 
different suites, eg "Vulnerable packages in the stable suite" points to 
https://security-tracker.debian.org/tracker/status/release/stable where you 
can tune your view.

So https://security-
tracker.debian.org/tracker/status/release/stable?filter=1&filter=high_urgency&filter=medium_urgency&filter=low_urgency&filter=unimportant_urgency&filter=unassigned_urgency&filter=undetermined_issues&filter=nodsa 
is probably the URL which will show you the highest number of security issues 
in stable ;)
 
> URLs would be highly appreciated.

not directly answering your questions, but maybe still useful:

http://security-team.debian.org/security_tracker.html


cheers,
	Holger

Attachment: signature.asc
Description: This is a digitally signed message part.


Reply to: