From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp2 ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms11 with LMTPS id mO+dB/CTUGCgeAAA0tVLHw (envelope-from ) for ; Tue, 16 Mar 2021 11:18:08 +0000 Received: from aspmx1.migadu.com ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp2 with LMTPS id 8MZtA/CTUGD7ZQAAB5/wlQ (envelope-from ) for ; Tue, 16 Mar 2021 11:18:08 +0000 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id AF8FF178D5 for ; Tue, 16 Mar 2021 12:18:07 +0100 (CET) Received: from localhost ([::1]:47360 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1lM7iA-0006sH-T0 for larch@yhetil.org; Tue, 16 Mar 2021 07:18:06 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:55182) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1lM7i0-0006s4-HA for guix-devel@gnu.org; Tue, 16 Mar 2021 07:17:56 -0400 Received: from mout.web.de ([212.227.17.11]:42633) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1lM7hy-0000oS-7p for guix-devel@gnu.org; Tue, 16 Mar 2021 07:17:56 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=web.de; s=dbaedf251592; t=1615893470; bh=gdSP7Tu2Uu2u+lSrtCkMma4nXq54rp/97EAwuo1Rvvc=; h=X-UI-Sender-Class:Subject:To:References:From:Date:In-Reply-To; b=DdcVu3tbGBjbKhFlLhLXgavVI7I6aNXvFhowlHrSvPcQaImZsGgx8Dhvss9sWJoo/ mcKo8D2VTKGH9tOgiax7nevYmm69JATDzFZUlmk8ZFNuLnHlcWAdbyLZ4Lq+tGUvrc AP628DkkFEcu99RyBJTWjAWYn1OYZaa6bRCgHB1c= X-UI-Sender-Class: c548c8c5-30a9-4db5-a2e7-cb6cb037b8f9 Received: from [192.168.178.74] ([5.146.192.139]) by smtp.web.de (mrweb106 [213.165.67.124]) with ESMTPSA (Nemesis) id 1N79RG-1llNlC2Rhs-017ItI for ; Tue, 16 Mar 2021 12:17:50 +0100 Subject: Re: [opinion] CVE-patching is not sufficient for package security patching To: guix-devel@gnu.org References: <9b9a43a584e2dc70488482fce5931b46abd0e006.camel@zaclys.net> From: Jonathan Brielmaier Message-ID: Date: Tue, 16 Mar 2021 12:17:49 +0100 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Icedove/78.7.1 MIME-Version: 1.0 In-Reply-To: <9b9a43a584e2dc70488482fce5931b46abd0e006.camel@zaclys.net> Content-Type: text/plain; charset=utf-8; format=flowed Content-Language: en-GB Content-Transfer-Encoding: quoted-printable X-Provags-ID: V03:K1:tjyNcSAfCDF91cXCBD/jsB2yxTWIzHsP6t9i4q0OcekXd7AzK+Q 5o2mpyi1JrtfEol3DDBi9t3YSQBYTtBil/VsQN8hBSr2MUkpqWIZ9lH+0H5b5IE0yz5XgiK YOpHic2HcefGyEGyxdKyIaNAgMuaoNkZ/OUovgnLrANTDtQrXdBcfZlEhQQDiU/OxNrUp4B bpROLFY+NXeXK6LV0+YiA== X-UI-Out-Filterresults: notjunk:1;V03:K0:qHf9APhR5P4=:0EiC69FH3505Xl0N/H85Zr 0WCIC7FaRvE3XQ0dOcZ5csXcwAWyYvegQZIS/m5Zvgv9N+/58cUrepeFnmVrGbAVBZUooVOsV GkIkuiR06VXVf5ZQPcTNhYoE6hsJJEOyvfIA8in6/g3g72+YOKKA3/3xrfiKVLRuFMA2x4XK1 hKKumEj+10TKzundgZwXcjRrbMVFrzm/Suy4lz/Cj779U58f8/RTSETf4naUdQ5hOToNoOy8W K9AfS/FGEZMKk5iL7TaG7NkkKk2JDM51VpQgK2i5l6+L206i5Yhh6fDTV2G+kVmTzQQG8odSB 5SJemiAvxZ9PaA0VepMlwYjM23jSTkWzblwUnVZd4JpG/vV3tU9cnmI+VjhUaY1I/f7ikaoch asSY2xN4iJjyiNzAcq5hAx3/wy8NOvSw+gG7N0j6QfEq6gcmbQMYYb+3Zemy8FDCYD1hq00l0 8SFD2VxwyGbzKpE2CY84pjhSJ11U01Ap/nZjRgp/USfn6L+ec5BV28X6uzw7o6d9vWpQd9Itx J8NxVIC/wUBfNu/Q4R9sw/GwLVHkIOK3onf4UCKZz7pNXBqmAyks+vzOhq9goUE2G3oy9AE4c jgVr/8yoeTxeWP+QS4VbS2/EZ64ZU2ceCnfiGJd9bdfcKajuCHEvd0XBy+nvoW3dVHy07Vfwp y8kC7SbITJOA8GiOV+34BY61Phvky0URITYUA36UCzJt1XPb8i3bvHe16jwm34SwlhA6iiOP0 I+HmQomqkmabt1f2Dergy+1EKYmrrpGVjgXYULBrYyGO1wWJJ1cE7A/9STbWza2IeRbxAjwol IQIGbKcQIwk7WozkN1mUMRa5KCg34c3Avv4Pe12tN4Z+lVvMG2PIVKBqmteXRXO/SMUqUesYm mciLYypOy+yEXoMCF9AeXqUrn1DgO+Ol/YmYWrDJw= Received-SPF: pass client-ip=212.227.17.11; envelope-from=jonathan.brielmaier@web.de; helo=mout.web.de X-Spam_score_int: -27 X-Spam_score: -2.8 X-Spam_bar: -- X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, NICE_REPLY_A=-0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: guix-devel@gnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+larch=yhetil.org@gnu.org Sender: "Guix-devel" X-Migadu-Flow: FLOW_IN ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=yhetil.org; s=key1; t=1615893487; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:list-id:list-help: list-unsubscribe:list-subscribe:list-post:dkim-signature; bh=gdSP7Tu2Uu2u+lSrtCkMma4nXq54rp/97EAwuo1Rvvc=; b=Or2PPudCwXCEqfxMaBBkvcWdJ0UZb4mdsBth5IVwZBuLQJQo127VjkX7eNevu2ykIFZD3C bsamDR2+NtfI2Se+vzXOzibW6Oo/A/bHfWUT/0oKeAScGarnKh08ghaK+KD+3Ja1Ni5eUC Ihl7Ha98k3VSwD/p5WNEcfF11cQo1V8ZyfiNBNX89VvPd+wG20TwNhRAL0fcaCPS10mLGT 7oBUEk5ChZAAjcCSqS0OsZ5knRmRF2O0uo/L7FQs6LfMHEhXv/humFjtq4xDkv4JSVI92N WbeIxFX+otQ8sM96xoI5DsoNlrJ7aXGUAlleY5NZLi3GDcB6LUKHdgJ6As1Uag== ARC-Seal: i=1; s=key1; d=yhetil.org; t=1615893487; a=rsa-sha256; cv=none; b=DnXlXSy3mK5d9ANhZ5aAlyhMFCOKQBl9bjB4IIFksniv9JETeIc5jPntSUKA7OWKDEOzav YhrwywQ1zr25RDveYYjCQslh4ifz3ZFJzGuDQsXi5dxGw6x/a/PYVOnJv90KyRzxvXgnx4 xlyPgM3WJjnWJltzD/M7kePhJOXAyI9XYKuo6ngeyI7h7RdYsYj2/UjXEnVioXQly28nn9 +fCwthE9WJX0Qh+CXXqtBtdmAiEQwS+fkC48eSHMubqfDpGAf9b6nkQG8+I4WrVe1EVZRD +ZnJ1pYJcaknHiPMFwegZRNb9A8ZGO5Z6q8uNN/7SkCEm00zfhFQtIsFAGwO1w== ARC-Authentication-Results: i=1; aspmx1.migadu.com; dkim=pass header.d=web.de header.s=dbaedf251592 header.b=DdcVu3tb; dmarc=pass (policy=none) header.from=web.de; spf=pass (aspmx1.migadu.com: domain of guix-devel-bounces@gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=guix-devel-bounces@gnu.org X-Migadu-Spam-Score: -3.10 Authentication-Results: aspmx1.migadu.com; dkim=pass header.d=web.de header.s=dbaedf251592 header.b=DdcVu3tb; dmarc=pass (policy=none) header.from=web.de; spf=pass (aspmx1.migadu.com: domain of guix-devel-bounces@gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=guix-devel-bounces@gnu.org X-Migadu-Queue-Id: AF8FF178D5 X-Spam-Score: -3.10 X-Migadu-Scanner: scn0.migadu.com X-TUID: T7wl++YvkQ4E On 16.03.21 12:10, L=C3=A9o Le Bouter wrote: > For these reasons, I suggest that we always strive to update packages > to their latest versions and that I think it is security relevant to > always do so. Of course, new code could *introduce* new vulnerabilities > but I am not trying to debate this, it's that to the best of the > upstream's knowledge chances are that the latest version will contain > more security fixes than older versions (if that upstream is actually > maintaining the project). I think the only two reasons against that are: time and CI/rebuilding. I think thats the reason why stuff like Gnome and others lower in the dependency tree are lacking behind... Being non-FHS and non-systemd makes updates for those stuff not easier and is maybe the third reason/root issue...