Hi everyone,
after having quite a bit of discussion here in discourse, on NixCon and in IRC I’d try a different ticket format. Vulnerability roundup 51 is split in 6 tickets:
- Vulnerability roundup 51: binutils-2.30 · Issue #49784 · NixOS/nixpkgs · GitHub (binutils)
- Vulnerability roundup 51: libtasn1-4.13 · Issue #49785 · NixOS/nixpkgs · GitHub (libtasn1)
- Vulnerability roundup 51: libtiff-4.0.9 · Issue #49786 · NixOS/nixpkgs · GitHub (libtiff)
- Vulnerability roundup 51: ncurses-6.1 · Issue #49787 · NixOS/nixpkgs · GitHub (ncurses)
- Vulnerability roundup 51: openjpeg-2.3.0 · Issue #49788 · NixOS/nixpkgs · GitHub (openjpeg)
- Vulnerability roundup 51: samba-4.7.10 · Issue #49789 · NixOS/nixpkgs · GitHub (samba)
Each ticket is intended to track updating, patching and backporting of that specific package independently.
I’m not sure if that is an improvement compared to the old roundups (all in one large ticket), so I’m glad to hear everyone’s opinions on this.
Pro:
- Scales better. The goal is to have many people working on security in parallel.
- Track updating/patching/backporting independently per package.
- Per-package discussion about patch availability etc.
Con:
- More tickets. It will be harder to keep an overview.