From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!.POSTED!not-for-mail From: Stefan Monnier Newsgroups: gmane.emacs.devel Subject: Re: [ANNOUNCE] Emacs 25.3 released Date: Tue, 12 Sep 2017 21:46:38 -0400 Message-ID: References: <87wp55t0un.fsf@petton.fr> <87tw07kikp.fsf@gnu.org> <161eff40ff05df7d5577e2456baa1676.squirrel@cloud103.planethippo.com> NNTP-Posting-Host: blaine.gmane.org Mime-Version: 1.0 Content-Type: text/plain X-Trace: blaine.gmane.org 1505267304 21096 195.159.176.226 (13 Sep 2017 01:48:24 GMT) X-Complaints-To: usenet@blaine.gmane.org NNTP-Posting-Date: Wed, 13 Sep 2017 01:48:24 +0000 (UTC) User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/26.0.50 (gnu/linux) To: emacs-devel@gnu.org Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Wed Sep 13 03:48:18 2017 Return-path: Envelope-to: ged-emacs-devel@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by blaine.gmane.org with esmtp (Exim 4.84_2) (envelope-from ) id 1drwmT-00046d-IT for ged-emacs-devel@m.gmane.org; Wed, 13 Sep 2017 03:47:57 +0200 Original-Received: from localhost ([::1]:39567 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1drwmZ-0007Ye-50 for ged-emacs-devel@m.gmane.org; Tue, 12 Sep 2017 21:48:03 -0400 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:39326) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1drwlz-0007YX-BK for emacs-devel@gnu.org; Tue, 12 Sep 2017 21:47:28 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1drwlw-0005AO-Mp for emacs-devel@gnu.org; Tue, 12 Sep 2017 21:47:27 -0400 Original-Received: from [195.159.176.226] (port=51998 helo=blaine.gmane.org) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1drwlw-00057G-FR for emacs-devel@gnu.org; Tue, 12 Sep 2017 21:47:24 -0400 Original-Received: from list by blaine.gmane.org with local (Exim 4.84_2) (envelope-from ) id 1drwlQ-0001II-10 for emacs-devel@gnu.org; Wed, 13 Sep 2017 03:46:52 +0200 X-Injected-Via-Gmane: http://gmane.org/ Original-Lines: 11 Original-X-Complaints-To: usenet@blaine.gmane.org Cancel-Lock: sha1:WcYregiYHAuqaFaC7ooyjUKgnTs= X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] [fuzzy] X-Received-From: 195.159.176.226 X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Original-Sender: "Emacs-devel" Xref: news.gmane.org gmane.emacs.devel:218168 Archived-At: > What do we not put a "vulnerability" package onto ELPA, then install this > by default. This way, new emacs releases would provide an automatic > mechanism for fixing vulnerabilities. And, for old Emacs, the advice would > be "M-x package-install vulnerability". I wouldn't call it "vulnerability" since it sounds like you're willingly installing a backdoor. But having a "security-patches" package might make sense. Stefan