On 14.05.2018 00:15, Ludovic Courtès wrote: > [...] shadow@4.6 is available and fixes CVE-2018-7169, consider ugprading ^typo > Should we satisfy ourselves with the current approach in the meantime? Release early and often would say yes. But I'm not an experienced developer. I have the feeling that guix lint does not cache the CVEs it fetches. I think it should. -- GPG: 7FDE 7190 2F73 2C50 236E 403D CC13 48F1 E644 08EC