All of lore.kernel.org
 help / color / mirror / Atom feed
From: Martin Jansa <martin.jansa@gmail.com>
To: openembedded-devel@lists.openembedded.org
Subject: Re: samba-essential upgrade or remove?
Date: Mon, 15 Mar 2010 09:20:39 +0100	[thread overview]
Message-ID: <20100315082039.GC3370@jama> (raw)
In-Reply-To: <ac9c93b11003150108v70781eb6re16d6212c454637e@mail.gmail.com>

On Mon, Mar 15, 2010 at 09:08:24AM +0100, Frans Meulenbroeks wrote:
> > 3.) Remove recipes for vulnerable software when no one is updating them in
> > time... This can be combined with option 2...
> 
> These are good plans, but I'm not sure if you will get volunteers for
> 2 and people will definitely complain if you do 3.

For security issues would be nice to adopt some form of Angstrom
blacklist class and put blacklist entry for all vulnerable recipes in
some security-blacklist.conf included from bitbake.conf.

This way it would be easy to show why the recipe is not available (CVE
noted in message shown by blacklist when some image tries to pull that
recipe).

Also it would allow easy blacklist removal for people who don't care
about security and easy to return recipe if someone cares and puts
enough time to fix that issue.

But current code would probably need to extend for blacklist based on
PN-PV not only PN (which someone already proposed for blacklisting old
recipes).

Regards,

-- 
uin:136542059                jid:Martin.Jansa@gmail.com
Jansa Martin                 sip:jamasip@voip.wengo.fr 
JaMa                         



  reply	other threads:[~2010-03-15  8:23 UTC|newest]

Thread overview: 22+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2010-03-08 12:00 samba-essential upgrade or remove? Holger Hans Peter Freyther
2010-03-08 12:42 ` Dr. Michael Lauer
2010-03-08 12:51   ` Holger Hans Peter Freyther
2010-03-15  3:46     ` Holger Hans Peter Freyther
2010-03-15  7:30       ` Frans Meulenbroeks
2010-03-15  7:46         ` Holger Hans Peter Freyther
2010-03-15  8:08           ` Frans Meulenbroeks
2010-03-15  8:20             ` Martin Jansa [this message]
2010-03-15  9:13           ` Dr. Michael Lauer
2010-03-15  9:30           ` Koen Kooi
2010-03-15  9:51             ` Frans Meulenbroeks
2010-03-15 15:58               ` Holger Hans Peter Freyther
2010-03-15 18:20                 ` Frans Meulenbroeks
2010-03-16  0:50                   ` Holger Hans Peter Freyther
2010-03-15  9:56             ` Holger Hans Peter Freyther
2010-03-15  8:53       ` Koen Kooi
2010-03-15 13:46         ` Mike Westerhof
2010-03-15 13:53       ` Mike Westerhof
2010-03-15 14:20         ` Koen Kooi
2010-03-15 14:38         ` Holger Hans Peter Freyther
2010-03-15 14:58           ` Frans Meulenbroeks
2010-03-15 15:53             ` Holger Hans Peter Freyther

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20100315082039.GC3370@jama \
    --to=martin.jansa@gmail.com \
    --cc=openembedded-devel@lists.openembedded.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.