From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from pigeon.gentoo.org ([69.77.167.62] helo=lists.gentoo.org) by finch.gentoo.org with esmtp (Exim 4.60) (envelope-from ) id 1JBflO-0004hz-C0 for garchives@archives.gentoo.org; Mon, 07 Jan 2008 00:22:46 +0000 Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id BA336E0492; Mon, 7 Jan 2008 00:22:43 +0000 (UTC) Received: from mo-p07-ob.rzone.de (mo-p07-ob.rzone.de [81.169.146.189]) by pigeon.gentoo.org (Postfix) with ESMTP id 76A70E0492 for ; Mon, 7 Jan 2008 00:22:43 +0000 (UTC) X-RZG-CLASS-ID: mo07 X-RZG-AUTH: hXn+rC1arvT7Lf9I/zKDqjrgIkrokD1Qxy5bIqfbp9I10BMNL35Kumb7+O8gwT7nDccLe+SW Received: from localhost (dynamic-unidsl-85-197-17-168.westend.de [85.197.17.168]) by post.webmailer.de (mrclete mo9) (RZmta 15.1) with ESMTP id m0717ck06JpmYU for ; Mon, 7 Jan 2008 01:22:42 +0100 (MET) (envelope-from: ) Date: Mon, 7 Jan 2008 01:22:34 +0100 From: Christian Faulhammer To: gentoo-dev@lists.gentoo.org Subject: [gentoo-dev] Re: Monthly Gentoo Council Reminder for January Message-ID: <20080107012234.7935871f@gentoo.org> In-Reply-To: <20080106234500.3fd78c16@snowcone> References: <20080101103002.083C4652C4@smtp.gentoo.org> <20080104004653.039f488e@snowcone> <20080104012750.63f4f23a@snowcone> <63044.68.54.223.178.1199445791.squirrel@www.aei-tech.com> <20080104210213.50a99e6b@snowcone> <61164.68.54.223.178.1199485599.squirrel@www.aei-tech.com> <20080104223754.3fb48b85@snowcone> <1199506818.7609.30.camel@inertia.twi-31o2.org> <20080105043233.0935d2f8@snowcone> <20080105124751.0bef4908@gentoo.org> <20080106003246.6e4b6425@snowcone> <20080106013630.7e0a504b@snowcone> <47803A61.7000600@gentoo.org> <20080106022402.01174707@snowcone> <47803DA9.10000@gentoo.org> <20080106023852.25b42e4b@snowcone> <47804281.3010000@gentoo.org> <20080106025825.2bedc1f1@snowcone> <47804C98.5050008@gentoo.org> <20080106073920.1008f064@snowcone> <20080107003541.43e12329@gentoo.org> <20080106234500.3fd78c16@snowcone> X-Mailer: Claws Mail 3.2.0 (GTK+ 2.12.1; i686-pc-linux-gnu) Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-dev@lists.gentoo.org Reply-to: gentoo-dev@lists.gentoo.org Mime-Version: 1.0 Content-Type: multipart/signed; boundary="Sig_/ch3O0hLs6MMJQQfmtXPE1su"; protocol="application/pgp-signature"; micalg=PGP-SHA1 X-Archives-Salt: 7956ac7a-ebe3-45c3-923c-568e4dfd3d31 X-Archives-Hash: db4e52eb5846211102ed81d885d857f1 --Sig_/ch3O0hLs6MMJQQfmtXPE1su Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: quoted-printable Hi, Ciaran McCreesh : > On Mon, 7 Jan 2008 00:35:41 +0100 > Christian Faulhammer wrote: > > is a list of closed security bugs > > where mips is still cced. 163 is the total number, where surely > > some duplicates can be found (PHP, Mozilla products), but we can > > assume that quite an extensive number of packages which are > > vulnerable stay still in the tree. > And how many of those have been fixed on mips without the Cc: being > removed? How many more of those would have been fixed had the bug not > been closed off? As you are so interested in those numbers, I humbly leave it to you to investigate in depth because I have to run a business. =20 A quick check on the 15 newest bugs showed exactly 1 package where mips was not lagging behind, where out of these only 2 are X applications. The bugs reach back until mid-November 2007 (CC date for arches). For the sake of fairness I took 15 bugs in a row from 170000 and greater. Where mips lagging behind in 4 packages (from April 2007, 1 X application), 2 packages where mips has been dropped completely (MySQL 5 e.g.). V-Li --=20 Christian Faulhammer, Gentoo Lisp project , #gentoo-lisp on FreeNode --Sig_/ch3O0hLs6MMJQQfmtXPE1su Content-Type: application/pgp-signature; name=signature.asc Content-Disposition: attachment; filename=signature.asc -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.7 (GNU/Linux) iD8DBQFHgXDQNQqtfCuFneMRAuZVAJ9bUiJKxdMypDUMt1UGS1BvXPQaqwCfQ2o/ dT5hKPeosKjszrppnISLjeo= =eRTF -----END PGP SIGNATURE----- --Sig_/ch3O0hLs6MMJQQfmtXPE1su-- -- gentoo-dev@lists.gentoo.org mailing list