Unhelpful update descriptions

Rahul Sundaram metherid at gmail.com
Thu Mar 14 15:47:46 UTC 2013


On 03/14/2013 11:34 AM, Przemek Klosowski wrote:
> Aah, wait a minute. I was tickled pink when I discovered that I can 
> look for vulnerability profile of a package by doing
>
> rpm --changelog -q php | grep CVE
>
> if RPM changelog is for packaging only this info wouldn't be there, 
> right? If so, what would you recommend as a replacement?

I wouldn't say it is for packaging *only* and CVE info is not 
consistently listed in the changelog anyway and a good replacement might 
be to just search CVE id in

https://admin.fedoraproject.org/updates

Rahul





More information about the devel mailing list