On Tue, 17 Aug 2010 10:46:10 +0400, Peter Volkov <p...@gentoo.org> wrote:

> В Пнд, 16/08/2010 в 18:04 +0000, Alexey Shvetsov (alexxy) пишет:
> > alexxy      10/08/16 18:04:52
> > 
> >   Modified:             ChangeLog
> >   Added:                drupal-5.23.ebuild drupal-6.19.ebuild
> >   Removed:              drupal-6.16.ebuild drupal-6.17.ebuild
> >                         drupal-5.22.ebuild
> >   Log:
> >   [www-apps/drupal] Version bump
> 
> Always reference bug number and mention people that spent time
> reporting problems in our bugzilla. Please, add bug # and attribution
> into ChangeLog. Also with version bump it's always good idea to keep
> previous version to allow re-installation of previous versions in the
> case of regressions.
> 
> https://bugs.gentoo.org/show_bug.cgi?id=323399
> 

That's rather https://bugs.gentoo.org/show_bug.cgi?id=332541

I agree that the bug # should be referenced, but as for removing the
old versions, that's something we usually ask people to do after
bumping packages with security issues to minimize the risk of people
installing possibly vulnerable versions.

-- 
Alex Legler | Gentoo Security / Ruby
a...@gentoo.org | a...@jabber.ccc.de

Attachment: signature.asc
Description: PGP signature

Reply via email to