Delay of security fixes?

Anything that pertains to Entropy, Equo or Sulfur

Moderator: Moderators

Delay of security fixes?

Postby darWIN » Sat Mar 09, 2013 16:28

Hi everyone,

I quite like the rolling release idea of Sabayon and the flexibility of gentoo. However there is one thing which makes me suspicious: How long does it take for security updates, to reach my system if I use sabayon-weekly? Do I have to wait for 13 days in a worstcase?
I downloaded a live iso today and installed firefox. And it is still version 18.0.1 while today 19.0.2 was release. A Windows and a Ubuntu machine already grabbed the update. Is this a weak spot? Or am I missing something?

Cheers,
darWIn
darWIN
Baby Hen
 
Posts: 2
Joined: Sat Mar 09, 2013 16:21

Re: Delay of security fixes?

Postby belcocco » Sat Mar 09, 2013 17:53

1)Sabayon is a rolling release. If installed once and updated regularly, you shouldn't need to reinstall new versions. Simply use the GUI package manager or command line if you choose, to keep up to date.
2)Sabayon is based on Gentoo's testing branch. Gentoo's testing branch is about on par with Debian's Sid (unstable branch) releases.
3)No big firm stands behind Sabayon.

You're not losing anything, please, be patient. :alien:
Ciao
belcocco
Advanced Hen
 
Posts: 290
Joined: Sat Nov 29, 2008 18:53
Location: Milan, Italy

Re: Delay of security fixes?

Postby colock » Sat Mar 09, 2013 18:19

I prefer a known-to-work but not-latest release than maybe-very-bugged and latest release.

I cannot understand this tendency to always run for the biggest numbers just for the sake of having bigger numbers...

i.e. why do you _need_ firefox 19.0.2? What features does it have that are not in firefox 18.0.1?
User avatar
colock
Simple Hen
 
Posts: 56
Joined: Mon Feb 25, 2013 12:01

Re: Delay of security fixes?

Postby darWIN » Sat Mar 09, 2013 18:31

I do not need the biggest numbers. But what I need is software with security fixes applied to it. Have a look at the security holes of version 18 http://www.mozilla.org/security/known-v ... refox.html - fixed in version 19.

I understand that there is no big company behind the distro. But... what makes linux security architecture superior to e.g. Windows and Mac is the fact, that security patches are available and installable within a very short time. Waiting 13 days for a already published ciritcal fix is quite insae...

I does not help me, that gentoos testing is as up to date as debians unstable - What matters is that fixes are (presumably) delayed.

Cheers
darWIN
Baby Hen
 
Posts: 2
Joined: Sat Mar 09, 2013 16:21

Re: Delay of security fixes?

Postby wolfden » Tue Mar 12, 2013 11:38

Firefox 19 is in limbo so it will get moved to main than to weekly. Security updates are always a concern and done in a timely manner. If something gets overlooked, feel free to file a package request for a package to get bumped.
User avatar
wolfden
Sharecropper
 
Posts: 8822
Joined: Sat Jan 14, 2006 0:55
Location: Midwest USA


Return to Entropy|Equo|Rigo Package Managers

Who is online

Users browsing this forum: No registered users and 1 guest