Re: How to manage security issues when the maintainer is not the developer

2008-04-16 Thread Lars Wirzenius
On ke, 2008-04-16 at 13:55 +0200, Andrea De Iacovo wrote: > How do you think a maintainer should manage security issues when he is > not the package developer? Should he/she either work alone to make > patches or wait for the upstream patches/relases that solve the bug? If the package maintainer i

Re: How to manage security issues when the maintainer is not the developer

2008-04-16 Thread Neil Williams
On Wed, 2008-04-16 at 13:55 +0200, Andrea De Iacovo wrote: > Hi all. > > How do you think a maintainer should manage security issues when he is > not the package developer? Should he/she either work alone to make > patches or wait for the upstream patches/relases that solve the bug? Notify upstre

Re: How to manage security issues when the maintainer is not the developer

2008-04-16 Thread Mark Brown
On Wed, Apr 16, 2008 at 01:55:51PM +0200, Andrea De Iacovo wrote: > How do you think a maintainer should manage security issues when he is > not the package developer? Should he/she either work alone to make > patches or wait for the upstream patches/relases that solve the bug? As ever, the best

How to manage security issues when the maintainer is not the developer

2008-04-16 Thread Andrea De Iacovo
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi all. How do you think a maintainer should manage security issues when he is not the package developer? Should he/she either work alone to make patches or wait for the upstream patches/relases that solve the bug? Andrea De Iacovo -BEGIN PGP SIG