Mailing List Archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [tlug] Debian OpenSSL critical security bug



Hung Nguyen Vu writes:

 > On Wed, May 14, 2008 at 7:52 AM, Josh Glover <jmglov@example.com> wrote:
 > > The lesson here is that distros should not add patches to upstream
 > > sources that made fundamental changes. Now to teach my fellow Gentoo
 > > developers that lesson... ;)

 > No, packagers really *should* work close with upstream projects.
 > The change is critical, not only fundamental.

Wishful thinking.  In fact most packagers are not developers of the
packages they are packaging, and they are packaging several packages.
Working closely with any upstream would involve dropping all their
other packaging work, or some other important aspect of their lives.
It's not going to happen.

In this particular case, there is a simple, arm's-length procedure
that would have been satisfactory: send a bug report.



Home | Main Index | Thread Index

Home Page Mailing List Linux and Japan TLUG Members Links