Re: Security Audit

david parsons (o.r.c@p.e.l.l.p.o.r.t.l.a.n.d.o.r.u.s)
22 Jun 1998 17:35:44 -0700


In article <linux.kernel.199806221833.LAA14346@dandelion.com>,
Leonard N. Zubkoff <lnz@dandelion.com> wrote:
>
> Every package I've fixed or merged diffs into for Red Hat they have gone to
> the maintainer if there is one. Often there isnt. Metamail has no maintainer
> and the nmh maintainers didnt seem at all interested in the holes in nmh. It
> varies. They _are_ going back however.
>
> I believe the Debian policy is identical on this issue
>
>So it sounds like what we are lacking then is a common repository for "fixed"
>versions of packages that are either unmaintained such as metamail or where
>there is no choice but to diverge from the author's version due to lack of
>interest in security fixes. I'd definitely like to see a single source
>repository for this.

Well, I'd be happy to provide and attempt to maintain a vender-neutral
home for 'em.

____
david parsons \bi/ Have T1, will travel.
\/

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu