From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp0 ([2001:41d0:8:6d80::]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) by ms0.migadu.com with LMTPS id GRNYFGGgW2AB2AAAgWs5BA (envelope-from ) for ; Wed, 24 Mar 2021 21:26:09 +0100 Received: from aspmx1.migadu.com ([2001:41d0:8:6d80::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp0 with LMTPS id sLMjD2GgW2DWAgAA1q6Kng (envelope-from ) for ; Wed, 24 Mar 2021 20:26:09 +0000 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id 6A03B21F15 for ; Wed, 24 Mar 2021 21:26:07 +0100 (CET) Received: from localhost ([::1]:43356 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1lPA4s-00026Z-3F for larch@yhetil.org; Wed, 24 Mar 2021 16:26:06 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:41636) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1lPA3m-0001GV-Tb for guix-devel@gnu.org; Wed, 24 Mar 2021 16:24:58 -0400 Received: from mail-pf1-x429.google.com ([2607:f8b0:4864:20::429]:44841) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1lPA3l-0000kS-Av for guix-devel@gnu.org; Wed, 24 Mar 2021 16:24:58 -0400 Received: by mail-pf1-x429.google.com with SMTP id m11so1138421pfc.11 for ; Wed, 24 Mar 2021 13:24:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=lZaUSs5azQASibTG6XFojuV6DCYxw6xHiUcGgsrHPbI=; b=qbHvj/PS2QdTq6ZlSVLF7xgZ/32Uwdc62A7tH/xAnHpu/a7bmGgyYUoGhWQITeLOjQ K1iSDEWv39IZi+Mf859Ue2qZyrwzHMBEvgr2G19+P35WdwFER5k+njQYt46FC4z+Uzkc TsGl4AXjPES8D26MCp2E8JBXkVIUVqI/87RFGAc6lOLZRtvR0PIxqsgFRMKcsIf0UE9v Od2soI++ChtUOvgrHuBUXsXrFTQD+lrm95hoGA2xD+4VYjruVU2PcYBLGoKUfqKLABuk fasxwNM3t8I0lNDwung5ix22NpxAKGDvLOg/yqk2RzL7WV8FBLFJ7ZYxl1Sf6SHGr1Je 4olQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=lZaUSs5azQASibTG6XFojuV6DCYxw6xHiUcGgsrHPbI=; b=ikMs1C9nHOACr1/JCrVKfK+YY15c9ebXS2Qn8TQdx5gvL2OthiVAAAwWHQ033aPXMd yydlfYheP1lB7fjlD+9gdI6a004+c/S4zOX1rh8IhNwoiziJ6slR5m7J9ONoo0oon1rt 0dT524b3IK/yCpppIwjbTYOFDtisQHaA25wm5GmCEhKQzDRoxBxsnU4Oul0Al+y4iF+d hINagAdHPXIpaXrzN19XTm+ywNqSR/HzplQSl1/KneFiyyuiTK3ZF02YluWoacUSdbbx cM1VNcM9okjaF07YX+uyRfM+evDCj2mTUL+77fRbHb41YHmm5Qz30HabQjbOba1Cx/tH asmw== X-Gm-Message-State: AOAM533GTqQuNgwNeK9wOAHN76v3Swqw5mFOVRANE5JHvaePQqTSPC48 B4I589SD/QdCtaVBe4BWSkSoc6SM+Dpg2NTUNUQ= X-Google-Smtp-Source: ABdhPJzWtKJ/DgeJ9NVPB8h+oHRGzc8iNhEyllNYWiR4k4rSUDLr7a/A5wRDJ7WkrDgbUei15sfg7+TRu6LS/YZ2kRo= X-Received: by 2002:a62:444:0:b029:1ed:7a00:d346 with SMTP id 65-20020a6204440000b02901ed7a00d346mr4644740pfe.27.1616617491187; Wed, 24 Mar 2021 13:24:51 -0700 (PDT) MIME-Version: 1.0 References: <9b9a43a584e2dc70488482fce5931b46abd0e006.camel@zaclys.net> <87v99qit39.fsf@netris.org> <877dm29iog.fsf@gnu.org> <20210322144404.1636b9cf@riseup.net> <875z1hv5tt.fsf@elephly.net> In-Reply-To: From: Vincent Legoll Date: Wed, 24 Mar 2021 21:24:40 +0100 Message-ID: Subject: Re: [opinion] CVE-patching is not sufficient for package security patching To: Leo Famulari Content-Type: text/plain; charset="UTF-8" Received-SPF: pass client-ip=2607:f8b0:4864:20::429; envelope-from=vincent.legoll@gmail.com; helo=mail-pf1-x429.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: guix-devel@gnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: guix-devel Errors-To: guix-devel-bounces+larch=yhetil.org@gnu.org Sender: "Guix-devel" X-Migadu-Flow: FLOW_IN ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=yhetil.org; s=key1; t=1616617568; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:in-reply-to:in-reply-to: references:references:list-id:list-help:list-unsubscribe: list-subscribe:list-post:dkim-signature; bh=lZaUSs5azQASibTG6XFojuV6DCYxw6xHiUcGgsrHPbI=; b=eiq4gIql+JJH+djsaVaJWqZN2E2eYKivwM9o9/wk8qnq/nOgSf/N4wIxjDQrTeaiTvz34G 8eH1rrMkuESYMj4NAyCE9fu+8Z0s5/vmKkwfQPs7Hlg/YbbJ4ngewZru4AVG8QESTY1E2M pwgXhNfzwyPvwyXsjD9PwsUiHbTK89JfsefimfYqqGRY5aSidmx7TLTFftHTj0S2Y3WvB/ VHlwTk7t8ATNH2fiBLBEOUVKScPC+B4UCtj/CGeuIgq888C2CkrtUaVfLidoUKfSrjKicl WFBECh5pwmgDk33zALGH110NA0I8BRWyiQSQzZlo/9ldcyvhXQxZQgQc3kRxGw== ARC-Seal: i=1; s=key1; d=yhetil.org; t=1616617568; a=rsa-sha256; cv=none; b=C84+gOjQGVq70YiyHPH5QlSnpo0Oc4+rC02KU0kRHo4G02Cg1TzwL8/Bnz2OOs80bIN+It aatdezNMd9LTtYAkTc5YghlnRDDHqMyDXkW8cRfLPUN8PfZ5b63+BvvTfjGG1lwBXWiJiB E262369Jw9rr3vG4r9pM7DbZjTZSmCiihJx/OH5iu/7P8pLgvwtnxO0P3nufACqaXcmId8 w+roT1TtaZ2SM61xb3C793l53SHMJgD/emyRHM90qZeXV8i+RK+76y0xhOSoEEcMJQdQzP VqlIIoJP52fUViUr7PQD+GhTwa1+pAwfxeX3DzdyxCSkQA/XyKVd076GIpgilg== ARC-Authentication-Results: i=1; aspmx1.migadu.com; dkim=fail ("headers rsa verify failed") header.d=gmail.com header.s=20161025 header.b="qbHvj/PS"; dmarc=fail reason="SPF not aligned (relaxed)" header.from=gmail.com (policy=none); spf=pass (aspmx1.migadu.com: domain of guix-devel-bounces@gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=guix-devel-bounces@gnu.org X-Migadu-Spam-Score: -1.87 Authentication-Results: aspmx1.migadu.com; dkim=fail ("headers rsa verify failed") header.d=gmail.com header.s=20161025 header.b="qbHvj/PS"; dmarc=fail reason="SPF not aligned (relaxed)" header.from=gmail.com (policy=none); spf=pass (aspmx1.migadu.com: domain of guix-devel-bounces@gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=guix-devel-bounces@gnu.org X-Migadu-Queue-Id: 6A03B21F15 X-Spam-Score: -1.87 X-Migadu-Scanner: scn0.migadu.com X-TUID: lnpmvlPBhewr Hello, On Wed, Mar 24, 2021 at 8:51 PM Leo Famulari wrote: > > We bought a handful of Overdrive 1000 in the past (they are no longer > > sold), and hosting was always an obstacle. > > I volunteer to host one or two workstation-type 64-bit ARM machines. I already volunteered (privately) to host the same (1 or 2 WS power-class), currently on ADSL uplink (so not for substitute distribution, only building), FTTH in the future, no UPS though. -- Vincent Legoll