Hi, > Same here. It looks that new GLSAs are released very infrequently. The > other problem ist that they are tied to the portage tree. When I use a > frozen portage tree to get repeatable builds, I'll never get new GLSA. > > I would favor check-glsa to use another means of communication (e.g., a RSS > feed).
Yes, I must confess that the security team is a bit shorthanded. As a solution for check-glsa you could just sync the appropriate folder. Craig