summaryrefslogtreecommitdiffstats
path: root/doc
diff options
context:
space:
mode:
authorThijs Kinkhorst <thijs@debian.org>2008-06-11 14:58:23 +0000
committerThijs Kinkhorst <thijs@debian.org>2008-06-11 14:58:23 +0000
commit591fa3468331c0d2b28c37d391af73435f04e568 (patch)
tree06f4537580ed53bf4795a0db2c14d1abd7116712 /doc
parentfc7aa4f18eb054ba6d72a2b4afbe16ced44cd257 (diff)
some language and rewraps
git-svn-id: svn+ssh://svn.debian.org/svn/secure-testing@9031 e39458fd-73e7-0310-bf30-c45bca0a0e42
Diffstat (limited to 'doc')
-rw-r--r--doc/bits_2008_06_x51
1 files changed, 27 insertions, 24 deletions
diff --git a/doc/bits_2008_06_x b/doc/bits_2008_06_x
index 8fc10b108e..3aabbc4129 100644
--- a/doc/bits_2008_06_x
+++ b/doc/bits_2008_06_x
@@ -1,7 +1,7 @@
Hi fellow developers,
-it's been some time since our last email.
-Much happened in regard to security support of Debian's testing distribution.
+It's been some time since our last email. Much happened regarding
+security support of Debian's testing distribution.
Level of security support for the testing distribution:
@@ -26,15 +26,16 @@ Security status of the current testing distribution (lenny):
With some pride we can say that testing was never in such good shape before
in regards to security. The tracker is reflecting known security issues in
the testing distribution[0]. The new announcement emails provide a notification
-for users, whenever a new security fix reaches testing, whether through
+for users whenever a new security fix reaches testing, whether through
migration from unstable or DTSA for testing-security. Also fewer packages are
-getting removed from testing, because of security issues.
+getting removed from testing because of security issues.
-In order to reach a wider audience with security updates for testing and because
-since beta1 of the lenny installer the testing-security repository is included in
-the apt-sources, a new mailing list hosted was created:
+In order to reach a wider audience with security updates for testing and
+because since beta1 of the lenny installer the testing-security repository is
+included in the apt-sources, a new mailing list has been created:
debian-testing-security-announce@lists.debian.org.
-We highly recommend that every user, who runs Debian testing and is concerned
+
+We highly recommend that every user who runs Debian testing and is concerned
about security subscribes to the debian-testing-security announcement list[1].
Note that this list is a replacement of the old secure-testing-announce list
hosted on alioth which was removed now.
@@ -55,18 +56,18 @@ with more details well before the release of lenny.
Embargoed issues and access to wider security information:
---------------------------------------------------------
-Parts of the Testing Security Team have been added to the team@security.debian.org
-alias and thus being also subscribed to the vendor-sec mailing list where
-embargoed security issues are coordinated and discussed between Linux
-vendors before being released to the public. The embargoed security queue
-on security-master will be used to prepare DTSAs for such issues. This is a
-major change as the Testing Security Team was not able to prepare updates
-for security issues under embargo before. If a DTSA was prepared for an embargoed
-issue in your package, you will either be contacted by us before the release or
-you will be notified through the BTS. Either way, you will most likely get an
-RC bug against your package including the patch used for the DTSA. This way
-you can prepare updates for unstable and the current unfixed unstable package does
-not migrate to testing, where it would overwrite the DTSA.
+Parts of the Testing Security Team have been added to the
+team@security.debian.org alias and thus being also subscribed to the vendor-sec mailing list where embargoed security issues are coordinated and discussed
+between Linux vendors before being released to the public. The embargoed
+security queue on security-master will be used to prepare DTSAs for such
+issues. This is a major change as the Testing Security Team was not able to
+prepare updates for security issues under embargo before. If a DTSA was
+prepared for an embargoed issue in your package, you will either be contacted
+by us before the release or you will be notified through the BTS. Either way,
+you will most likely get an RC bug against your package including the patch
+used for the DTSA. This way you can prepare updates for unstable and the
+current unfixed unstable package does not migrate to testing, where it would
+overwrite the DTSA.
Freeze of lenny coming up:
@@ -89,10 +90,12 @@ and if we should ask you to upload a DTSA, use the embargoed upload queue
Handling of security issues in the unstable distribution:
---------------------------------------------------------
-First of all, unstable does not have official security support. The illusion that
-the Debian Testing Security Team also officially supports unstable is not true.
-Security issues in unstable, especially when the package is not in testing, are
-not regarded as high urgency and only dealt with, when there is enough spare time.
+First of all, unstable does not have official security support. The illusion
+that the Debian Testing Security Team also officially supports unstable is not
+true. Security issues in unstable, especially when the package is not in
+testing, are not regarded as high urgency and only dealt with when there is
+enough spare time.
+
However, it is true that we let most of our security updates migrate through
unstable to prevent doubled workload here. For this purpose, we urge every
maintainer to upload their security fixes with high urgency and mention the CVE

© 2014-2024 Faster IT GmbH | imprint | privacy policy