Security release criterion proposal

Kevin Kofler kevin.kofler at chello.at
Wed May 18 21:03:57 UTC 2011


Simo Sorce wrote:
> Is it unthinkable to respin the images with those fixes ?
> Usually the patches are quite simple to backport, and we are talking
> about a limited set of bugs (remote root exploit on install) after all.

Then we'd need a second (or third, if the Features repo finally happens) 
update channel with only GA + backported security fixes. Do you volunteer to 
maintain that? And what about the required resources, e.g. the extra Koji 
build target? And this does not even address spinning and distributing the 
respun images themselves.

Sure, it's theoretically a good idea, but unfortunately I'm not convinced of 
its practicality.

        Kevin Kofler



More information about the devel mailing list