Re: Mozilla products in Debian (was: A question for the list:)



On Friday 05 November 2010 08:13:41 Camaleón wrote:
On Fri, 05 Nov 2010 07:54:29 -0500, Boyd Stephen Smith Jr. wrote:
In <pan.2010.11.05.08.38.21@xxxxxxxxx>, Camaleón wrote:
On Fri, 05 Nov 2010 00:30:11 -0500, Boyd Stephen Smith Jr. wrote:
There is a third choice, I guess: Ship firefox / thunderbird in
non-free. Support for non-free is best-effort, which basically means
that if upstream is willing to fix it then the security team /
maintainers will package it. This basically results in Debian
stable's non-free containing software with known security
vulnerabilities that Mozilla is unwilling to fix.

How about "volatile"? :-?

ClamAV packages are there for that precisely reason (they need to be
updated -security fixes- very often).

Firstly, only packages that are already in the official repository are
included in volatile.

Icedove and Iceweasel are.

Yes, but the original request was for Firefox and Thunderbird.

Second, volatile is for packages that need
frequent, non-security updates to maintain functionality (at least in
the eyes of some users). (Updating the virus signature database is not
considered a security update.)

AFAIK, ClamAV packages are fully upgraded (not only for fetching new
signatures but the whole program).

In any case, they are not "security upgrades" in the Debian sense. They do
not fix vulnerabilities in the ClamAV package.

FWIW, even ClamAV in volatile avoids new upstream versions unless old versions
are unable to function.

Thirdly, the policy of no new upstream
versions after release isn't changed for volatile. (It is changed for
volatile-sloppy.)

And that is what people wants to be improved :-)

No. That's NOT what those who know and love Debian stable want. The lack of
upstream changes is one of the main reasons I use stable on servers.

Finally, updating the Debian package *more often* is
the opposite of coming into trademark compliance.

You know what other "non-rolling" distros do in this case: stock
versions of the programs remain unchanged and maintained for the time the
distribution is supported but in pararel there are satellite repositories/
forges.

1. Backports contains new upstream versions compiled in a released Debian
environment. When Squeeze is released we should have an official backports
service.

2. No one is preventing anyone from creating such repositories. Debian is a
volunteer project. Existing DDs seem to like the status quo at least to some
degree (existing policy can be changed if there is sufficent support for a
change). New volunteers can work on whatever they like and the process of
becoming a DD is well-documented and always open.
--
Boyd Stephen Smith Jr. ,= ,-_-. =.
bss@xxxxxxxxxxxxxxxxx ((_/)o o(\_))
ICQ: 514984 YM/AIM: DaTwinkDaddy `-'(. .)`-'
http://iguanasuicide.net/ \_/

Attachment: signature.asc
Description: This is a digitally signed message part.



Relevant Pages

  • Re: New user Q: Best way to stay up to date on "testing"?
    ... > understand the entire Debian environment and need a little advise. ... > I was reading the security FAQ and am somewhat alarmed to find (if I ... > packages, most of which seem to be related to X (we won't ever be using X ... Only install the packages that your really need to have. ...
    (Debian-User)
  • Debians policy regarding security updates
    ... I can't quite figure out the policy of Debian with regard to security ... Debian will attempt to prepare a fix ... all packages in the latter group ...
    (comp.os.linux.security)
  • Re: Need newer software that included with stable (that isnt at backports.org)
    ... only get security updates. ... All the security updates are served through ... Consequently, fixes for packages ... The Debian ...
    (Debian-User)
  • New user Q: Best way to stay up to date on "testing"?
    ... understand the entire Debian environment and need a little advise. ... I was reading the security FAQ and am somewhat alarmed to find (if I ... new packages are more likely to contain ... apt-get -s upgrade I'm told that apt wants to upgrade about 15 packages, ...
    (Debian-User)
  • Re: We need a new subject- bug fixes
    ... I'm not talking about additional packages - this is in reference to your comment about not deviating from upstream. ... Sendmail is enabled by default but not configured to connect to external ports in order to deliver local mail for root user but avoid the additional security issues with connecting to external ports by default. ...
    (Fedora)