On Tue, 2016-09-06 at 22:28 -0400, Antoine Beaupré wrote: > I am a bit surprised to see this - are ircd packages sponsored now? > There's a similar issue in Charybdis and I deliberately marked it as > unsupported in LTS because, AFAIK, no customer expressed the need to > support those yet.
If Freexian customers don't use it then it's low priority for those of us paid through Freexian. But that doesn't mean it should be marked unsupported by the LTS team. > I'd be glad to see if we can update charybdis in Wheezy as well, but to > be honest, i think people running IRCs on wheezy are really looking for > trouble, both in the case of charybdis and inspircd. I think they should > be marked as unsupported, because they are not supported upstream. > > I had an interesting conversation with the inspircd maintainers > recently, over IRC: they are basically saying that 2.0.5 is full of > security holes, and they do not bother with issuing CVEs, so it's really > hard to tell what version if affected by what. This, on the other hand, is a good reason to make it explicitly unsupported (or, if some LTS users really do want it, to move to a supportable upstream version). Ben. > It's only because I requested those CVEs that this issue propped up on > Debian's radar at all, btw... > > A. -- Ben Hutchings For every action, there is an equal and opposite criticism. - Harrison
signature.asc
Description: This is a digitally signed message part