"Julian H. Stacey" <j...@berklix.com> writes:
> But alerting pre existing issues just after new releases will reduce
> security for all who can't spare enough time, so must skip the flood.

We can't always hold back a release, even when there are known issues.
Users are waiting for it, release engineers need to move on to other
work, and the very fact that we're holding it back with no explanation
and no visible activity tells people that something is up.  Also, how
long are we going to hold it?  There is *never* a point in time where
the security team does not know of or suspect at least one issue in a
current or upcoming release.  The line has to be drawn somewhere.  In
the case of 10.2, the three ENs published on 2015-08-18 were for issues
that would only affect a very small minority of users, and the expat
issue was not raised until the release was almost complete.  The ENs and
SAs published on 2015-08-25 were either unknown or still in the very
early investigation phase at the time of the release.

DES
-- 
Dag-Erling Smørgrav - d...@des.no
_______________________________________________
freebsd-security@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscr...@freebsd.org"

Reply via email to