From mboxrd@z Thu Jan 1 00:00:00 1970 From: Alex Vong Subject: Re: Announcement regarding the oss-security mailing list Date: Sun, 12 Feb 2017 14:44:17 +0800 Message-ID: <87fujjdi2m.fsf@gmail.com> References: <20170211194400.GA10091@jasmine> Mime-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:50100) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ccnte-0003M6-5F for guix-devel@gnu.org; Sun, 12 Feb 2017 01:44:31 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1ccntb-0000jW-11 for guix-devel@gnu.org; Sun, 12 Feb 2017 01:44:30 -0500 Received: from mail-pf0-x241.google.com ([2607:f8b0:400e:c00::241]:35613) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1ccnta-0000jQ-Qj for guix-devel@gnu.org; Sun, 12 Feb 2017 01:44:26 -0500 Received: by mail-pf0-x241.google.com with SMTP id 68so3117181pfx.2 for ; Sat, 11 Feb 2017 22:44:26 -0800 (PST) In-Reply-To: <20170211194400.GA10091@jasmine> (Leo Famulari's message of "Sat, 11 Feb 2017 14:44:00 -0500") List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Leo Famulari Cc: guix-devel@gnu.org --=-=-= Content-Type: text/plain Leo Famulari writes: > I think that several of us are subscribed to oss-security as part of our > effort to learn about upstream security issues in a timely manner. > > A couple days ago, MITRE decided to stop assigning CVEs from the list: > > http://seclists.org/oss-sec/2017/q1/351 > > So, I expect that we will see fewer bugs sent to oss-security, and Guix > developers interested in package security may need to adjust their > approach to learning about such bugs. > > Let's share some tips on where to find this information. > > I look at the lwn.net security advisories, the Debian security-announce > mailing list, `guix lint -c cve`, the upstream bug trackers of a handful > of packages, and even some Twitter personalities. > > What about you? I subscribed to Debian and Gentoo security announcement list. I try to keep the subscription list short, since I already get a lot of emails, and I only read them only in the weekend. --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEdZDkzSn0Cycogr9IxYq4eRf1Ea4FAligBEEACgkQxYq4eRf1 Ea6twQ/+IPQWf2CzvY2hlMglPWpJY1x/yYA7xmIdRWOOGpJSKBtdIfnGSRtxOPos YfYdKUghhEnhOdg8MYNEZYI/NMvU2xnH/PMdf4ne3sPoOOBFtb0TS4nk5QAQYYOV BvBX5koSFptyi4cHza77tgZRUVV6v9UI30jQlEgUggevTXWmMZiQ2labg45fnKqv EWOySXrP3qZsr3cSdbSqvgI8cqjdeoy0Ou/19585djXmJFlHAdwfJOYbKrohiGFP Ox/UwEhrVjBxrPZcPK1L+3fQ4c2w71UskZR+fFmXk6L/L5+JoJHO67hoynS391FO AQDrZmd5J8zzmgdQ+HKSzy713ZIF/GPmHS52tbwMG1VF3EAJl8sagxJLQQm/qtXm F5tXdxJJEqtwe9kdQabi0svZKf5eRdwFgn6IeP+7BY13IYdq37BJbFvZWXXHoKiA G00gGxhbDUbXQDOHQe7e/H9BfrNN5eH8rWsTfUzEKPjZeUd+j+Z6FwwOX9Ha1EPY uHma21+yGqH3vEwIEJhr/V0YOdwQUDRCsLUeOphpftxgsvtq7UdVGhXpM7jrWtJJ Q7muloLes6T74pobBVM7gMZZ45S1v7m4sPpQil2XCzVvyxyrjbEFsDJQARcdvxjY De2pY2WZtMdKnxkQh7HvU3PgS7/zllF7AwTOwV6D1dRRAuGva0Q= =CbWw -----END PGP SIGNATURE----- --=-=-=--