From: Adrian Bunk <bunk@stusta.de>
To: Alexander Kanavin <alex.kanavin@gmail.com>
Cc: Patches and discussions about the oe-core layer
<openembedded-core@lists.openembedded.org>,
openembedded-architecture
<openembedded-architecture@lists.openembedded.org>
Subject: Re: [Openembedded-architecture] Does YP provide security support for stable and LTS branches?
Date: Mon, 9 Mar 2020 02:23:08 +0200 [thread overview]
Message-ID: <20200309002308.GD1425@localhost> (raw)
In-Reply-To: <CANNYZj_4sTc9vjhm1+S1GbjN=8SjChWt+gksxxKLXEZXeK9nPQ@mail.gmail.com>
On Sun, Mar 08, 2020 at 11:08:08PM +0100, Alexander Kanavin wrote:
> On Sun, 8 Mar 2020 at 22:46, Adrian Bunk <bunk@stusta.de> wrote:
>
> > It is on YP to make it clear to users whether or not Yocto comes with
> > the same set of security guarantees as distributions like Ubuntu or
> > Debian.
> > If it is the duty of every user of Yocto to track and fix CVEs,
> > then this has to be stated clearly instead of implying the opposite.
> > This gives users the opportunity to mitigate, instead of unknowingly
> > shipping insecure products.
> >
>
> Do you have any actual evidence for actual users shipping insecure products
> because they mistakenly believe Yocto takes care of security for them?
Nothing to discuss in public.
> This
> has been the situation from the start of the project, certainly this was
> the case 5 years ago when I joined it, and the only person ever to make an
> issue out of it is you. Everyone else seems to understand the deal they're
> getting by using Yocto without a commercial support contract.
>...
You are saying that 'track and fix CVEs' is on users.
Let's check what YP is telling users.
Click on the "Is Yocto Project for you?" link on the YP frontpage:
https://www.yoctoproject.org/is-yocto-project-for-you/
13. Yocto Project follows a strict release schedule incorporating
security patches in all supported releases. This predictability is
crucial for projects that are based on Yocto Project and allows the
development teams to plan their activities. Developers can choose which
Yocto Project branch on which to base their activities as a function of
their needs. The development branch will ensure access to the latest
features while the stable branches will reduce the pace of changes. CVEs
(common vulnerabilities and exposures) issues are supported for the
latest 2 releases.
> Alex
cu
Adrian
next prev parent reply other threads:[~2020-03-09 0:23 UTC|newest]
Thread overview: 27+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-02-23 19:34 [RFC][PATCH 1/2] nss: Move to meta-oe Adrian Bunk
2020-02-23 19:34 ` [RFC][PATCH 2/2] nspr: " Adrian Bunk
2020-02-24 0:25 ` [RFC][PATCH 1/2] nss: " Khem Raj
2020-02-24 5:17 ` Adrian Bunk
2020-02-24 16:32 ` akuster808
2020-02-27 13:27 ` Adrian Bunk
2020-02-27 14:03 ` Alexander Kanavin
2020-03-04 9:05 ` Adrian Bunk
2020-03-04 9:36 ` Alexander Kanavin
2020-03-04 11:32 ` Adrian Bunk
2020-03-04 12:13 ` Alexander Kanavin
2020-03-04 14:01 ` Does YP provide security support for stable and LTS branches? Adrian Bunk
2020-03-04 16:00 ` Alexander Kanavin
2020-03-04 17:24 ` Adrian Bunk
2020-03-04 20:26 ` [Openembedded-architecture] " akuster808
2020-03-06 10:04 ` Adrian Bunk
2020-03-06 10:36 ` Richard Purdie
2020-03-08 21:46 ` Adrian Bunk
2020-03-08 22:08 ` Alexander Kanavin
2020-03-09 0:23 ` Adrian Bunk [this message]
2020-03-09 7:29 ` Ayoub Zaki
2020-03-09 9:53 ` Alexander Kanavin
2020-03-09 12:45 ` Richard Purdie
2020-03-10 16:11 ` Ross Burton
2020-03-10 19:45 ` Ayoub Zaki
2020-03-11 14:53 ` Ross Burton
-- strict thread matches above, loose matches on Subject: below --
2020-03-09 10:01 Rich Persaud
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20200309002308.GD1425@localhost \
--to=bunk@stusta.de \
--cc=alex.kanavin@gmail.com \
--cc=openembedded-architecture@lists.openembedded.org \
--cc=openembedded-core@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox