|
Message-ID: <20190621150836.ieiciui3n6vrd5wb@matica.foolinux.mooo.com> Date: Fri, 21 Jun 2019 08:08:36 -0700 From: Ian Zimmerman <itz@...y.loosely.org> To: oss-security@...ts.openwall.com Subject: Re: Thousands of vulnerabilities, almost no CVEs: OSS-Fuzz On 2019-06-21 10:57, Simon McVittie wrote: > If upstream projects have a stable branch that is genuinely stable > and bugfix-only to minimize the risk of regressions, and encourage > downstream distributions to align on the latest stable branch during > their development phase, then I think that goes a long way towards this. > If I understand correctly, PostgreSQL is one of the canonical examples of > a project that does this, and gets its upstream point releases included > in stability-focused projects like Debian as-is. Doesn't this simply shift the work of backporting ("crazy and bound to always fail in the end") from the distro maintainer to the upstream stable branch maintainer? He/she is more like "midstream" working in that role. -- Please don't Cc: me privately on mailing lists and Usenet, if you also post the followup to the list or newsgroup. To reply privately _only_ on Usenet and on broken lists which rewrite From, fetch the TXT record for no-use.mooo.com.
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.