[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [SECURITY] [DSA 1680-1] New clamav packages fix potential codeexecution



This one time, at band camp, Jim Popovitch said:
> On Wed, Dec 10, 2008 at 13:21, Dominic Hargreaves <dom@earth.li> wrote:
> > I don't really understand your question. There is no separate security
> > archive for volatile, as I understand it.
> 
> Oddly enough I understood Tony, yet I don't understand the
> Volative+ClamAV situation.  Can someone definatively state what is the
> holdup/situation/reasoning for why the latest ClamAV release has been
> pushed to all the mirrors but not updating via apt.

[Dropping -security, as this really isn't on topic for that list]

I might be wrong, but as I understand it, the process is that a
maintainer or team does an upload, and then the package goes to the
volatile autobuilder network, and then when enough architectures have
built it, an announcement is written and mailed out, and the Packages
file is updated at the same time.  A hold up in any of these steps could
delay the process.

It appears in this paricular case that the volatile maintainers are
waiting on at least an announcement draft.  I'll write that tonight, and
see if anything else needs to be done.

Cheers,
-- 
 -----------------------------------------------------------------
|   ,''`.                                            Stephen Gran |
|  : :' :                                        sgran@debian.org |
|  `. `'                        Debian user, admin, and developer |
|    `-                                     http://www.debian.org |
 -----------------------------------------------------------------

Attachment: signature.asc
Description: Digital signature


Reply to: