"security" repo

Matthias Runge mrunge at matthias-runge.de
Tue Jul 17 11:02:02 UTC 2012


On 17/07/12 02:40, Mike Manilone wrote:
> Hi, list
> 
> I don't want too many updates so I disable the "updates" repo. But
> later I found that "fedora" repo has no updates so I couldn't get any
> security updates.

I'm not really sure, this would give you, what you really want;
especially, it may even lead to "broken dependencies", because not
every package is accessible just through "fedora" and "security" channels.

Take an application and assume, there's a security flaw discovered.
It'll probably get fixed in the latest, sometimes even in some versions;
this may not include the version packaged in the distribution.
Then a packager would upgrade to a newer version, introducing newer
features, which you don't want to get. The never version may require
other packages, which are currently unavailable in fedora or security repos.

If you'd like to get security fixes backported, you'll probably want a
supported (i.e. paid) distro, e.g. RHEL or it's free clones Scientific
Linux, or CentOS.

Please note: you will still get (many) updates and should install them
all, but you won't get newer features.

I'm skeptic, if a pure "security" repo for fedora would work that well.
-- 
Matthias Runge <mrunge at matthias-runge.de>
               <mrunge at fedoraproject.org>




More information about the devel mailing list