All of lore.kernel.org
 help / color / mirror / Atom feed
From: Andrew Cooper <andrew.cooper3@citrix.com>
To: Agostino Sarubbo <ago@gentoo.org>
Cc: xen-devel@lists.xen.org
Subject: Re: security bugs and release
Date: Wed, 26 Jun 2013 00:09:54 +0100	[thread overview]
Message-ID: <51CA2342.3020902@citrix.com> (raw)
In-Reply-To: <2052847.SzM2x6sscC@devil>

On 25/06/2013 18:07, Agostino Sarubbo wrote:
> Hello,
>
> I'd like to know why when there is a new advisory you just release a patch 
> instead of a new release.
>
> This, in my opinion creates only confusion. For example, if I'm running 4.2.1 
> I don't exatly know which patches have been applied. If you say, this is fixed 
> in 4.2.2 I know that if I'm run that version, I'm fine.
>
> Is there a real reason because you don't make a new release?

I would be interested if you could provide examples of upstream projects
which do issues brand new releases for every security fix, rather than
applying the patch(es) to appropriate stable trees.  Downstream distros
certain do issue hotfixes/updates when they deem appropriate.

If there is any confusion regarding patches and versions, please refer
to http://wiki.xen.org/wiki/Security_Announcements which provides all
details (although I note it is out of date with respect to XSA-57).

~Andrew

  reply	other threads:[~2013-06-25 23:09 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2013-06-25 17:07 security bugs and release Agostino Sarubbo
2013-06-25 23:09 ` Andrew Cooper [this message]
2013-06-25 23:56   ` Agostino Sarubbo
2013-06-26  9:21 ` Ian Campbell
2013-06-26 13:54   ` Pasi Kärkkäinen
2013-06-26 15:21     ` Agostino Sarubbo
2013-06-26 15:24   ` Agostino Sarubbo

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=51CA2342.3020902@citrix.com \
    --to=andrew.cooper3@citrix.com \
    --cc=ago@gentoo.org \
    --cc=xen-devel@lists.xen.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.