From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from lists.gentoo.org (pigeon.gentoo.org [208.92.234.80]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by finch.gentoo.org (Postfix) with ESMTPS id 5F2B1158020 for ; Fri, 11 Nov 2022 22:07:28 +0000 (UTC) Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id 08D2FE09C9; Fri, 11 Nov 2022 22:07:24 +0000 (UTC) Received: from mail-pg1-x532.google.com (mail-pg1-x532.google.com [IPv6:2607:f8b0:4864:20::532]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by pigeon.gentoo.org (Postfix) with ESMTPS id D579DE086F for ; Fri, 11 Nov 2022 22:07:23 +0000 (UTC) Received: by mail-pg1-x532.google.com with SMTP id b62so5434302pgc.0 for ; Fri, 11 Nov 2022 14:07:23 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :from:to:cc:subject:date:message-id:reply-to; bh=8TYj0yS0MHRFtOViDb5F0rKpblowAhKEhRZylitfWQk=; b=kayb4MnDaLwqp9CGOhdSrATEMowA07YhAEjUD0yvd67Kb5e1RsXjLW4iLs7sZd68Bb DKnIOUN5+vyY93YRQ7kmf7b09e78kcmL9zA3BtEZN6KcqF9xBogfrqhC0G7BAyFkbzH9 p/s1H6ag7p758cXHEw93oZCJUqzE7ZU55jM/fNdTNtMN4nuYXK7h1jkb6LR3Fi0//vbH sJpDw1bBqkAvjpSBOgl/YZh7HtN+y7AlARQwyXQrz40Dfac/g3E8u7+9tc91iuzveH/1 Fh49gMPpfsvhitGByuW4xA1mPcm246Lgjdp1TR4lO5x6i/Y4fT1oXyjnIoaI8dKOS++2 NYNA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=8TYj0yS0MHRFtOViDb5F0rKpblowAhKEhRZylitfWQk=; b=qrmD76fL/1G69tWMDE/mTjbBFY3MWoKjUa59ynN2KdnRqdzTXXILhL9IyVAGEeRSuT hdOSQIg+mVmCrFK01fLqssIBvbqO1kHBEtEUUkxtGYnXvMDAaFxakhFcopeZFS69JNPJ +g81po6WeXoqLwnyINToxqjJsvg44nLQZxK0vOL2+t/doxl1XOBI9adJk8RsJlRBCIzt dtdCWGcRgTSDZpv7j0tMY+/I/nN5k2zfWcDMPsKlKgdQh1iW2f8r2z2dqWovuxoI2aIu Q2vZhp460Ho1kWpg6AuCkMIA3C7Yy5X90ZJ8kq3V2Nnbi2Ht4cKRdla3C40WV6sOx1Ry UJhQ== X-Gm-Message-State: ANoB5pkg2DAnC9NOonjRO8Y3riYSHq4WQH1g01IS2Z9amXxNKhyfteHK +bHPB/O2LCv3jIvQyIBPx/GZ34jXpNRluMQIdYkG7yY5 X-Google-Smtp-Source: AA0mqf4en4O43etznbVNVmMqJ0p70KnSVhVq94X5n0uBYmt21StUu2++HhRvwb4Ml/oial7nmVe1dcyDwBGJjb5rVMM= X-Received: by 2002:a63:d253:0:b0:46f:6f56:2376 with SMTP id t19-20020a63d253000000b0046f6f562376mr3289678pgi.582.1668204442359; Fri, 11 Nov 2022 14:07:22 -0800 (PST) Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-dev@lists.gentoo.org Reply-to: gentoo-dev@lists.gentoo.org X-Auto-Response-Suppress: DR, RN, NRN, OOF, AutoReply MIME-Version: 1.0 References: <626eaf6c-f41e-3dfd-2750-39c4522175c1@gentoo.org> In-Reply-To: From: Gordon Pettey Date: Fri, 11 Nov 2022 16:06:45 -0600 Message-ID: Subject: Re: [gentoo-dev] [RFC] A new GLSA schema To: gentoo-dev@lists.gentoo.org Content-Type: multipart/alternative; boundary="00000000000033217e05ed391da2" X-Archives-Salt: fce726f4-6c1a-45c1-b8d8-91d863b6cfc6 X-Archives-Hash: 08e4ef70601090536de55a2b5ee7c2f6 --00000000000033217e05ed391da2 Content-Type: text/plain; charset="UTF-8" On Thu, Nov 10, 2022 at 6:27 PM John Helmert III wrote: > On Thu, Nov 10, 2022 at 09:49:27PM +0100, Jonas Stein wrote: > > On 10/11/2022 03:27, John Helmert III wrote: > > > The first GLSA in glsa.git is GLSA-200310-03, the third GLSA of > > > October 2003. It used roughly the same format of the GLSAs we release > > > today, in 2022, making that format almost as old as me. > > > > IFF we change the format, we should not invent a new standard [1] but > > use existing one like CSAF [2] > > > > [1] https://imgs.xkcd.com/comics/standards.png > > [2] https://oasis-open.github.io/csaf-documentation/ > > We're not inventing a new "standard", we're upgrading the format we use > to distribute GLSAs. > Standard, format, semantics. You are producing a new schema in a field where at least one usable (and already-improved?) schema exists. NIH? --00000000000033217e05ed391da2 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable
On Thu, Nov 10, 2022 at 6:27 PM John Helmert III <ajak@gentoo.org> wrote:
On Thu, Nov 10, 2022 at 09:49:27PM = +0100, Jonas Stein wrote:
> On 10/11/2022 03:27, John Helmert III wrote:
> > The first GLSA in glsa.git is GLSA-200310-03, the third GLSA of > > October 2003. It used roughly the same format of the GLSAs we rel= ease
> > today, in 2022, making that format almost as old as me.
>
> IFF we change the format, we should not invent a new standard [1] but =
> use existing one like CSAF [2]
>
> [1] https://imgs.xkcd.com/comics/standards.png > [2] https://oasis-open.github.io/csaf-documen= tation/

We're not inventing a new "standard", we're upgrading the= format we use
to distribute GLSAs.

Standard, format, semantics= . You are producing a new schema in a field where at least one usable (and = already-improved?) schema exists. NIH?
--00000000000033217e05ed391da2--