Re: Security releases for ecosystems that use static linking

2025-07-13 Thread Philipp Kern
On Fri, Dec 22, 2023 at 09:54:45AM +0100, Moritz Muehlenhoff wrote: > One solution which has been discussed in the past is to import a full copy > of stable towards stable-security at the beginning of each release cycle, > but that is currently not possible since security-master is a Ganeti VM > an

Re: Security releases for ecosystems that use static linking

2024-03-20 Thread Moritz Muehlenhoff
Thorsten Alteholz wrote: [ Adding DSA to the CC list ] > On Mon, 18 Mar 2024, Emilio Pozuelo Monfort wrote: > > > One solution which has been discussed in the past is to import a full copy > > > of stable towards stable-security at the beginning of each release cycle, > > > but that is currently

Re: Security releases for ecosystems that use static linking

2024-03-18 Thread Thorsten Alteholz
On Mon, 18 Mar 2024, Emilio Pozuelo Monfort wrote: One solution which has been discussed in the past is to import a full copy of stable towards stable-security at the beginning of each release cycle, but that is currently not possible since security-master is a Ganeti VM and the disk requireme

Re: Security releases for ecosystems that use static linking

2024-03-18 Thread Moritz Muehlenhoff
On Mon, Mar 18, 2024 at 01:13:15PM +0100, Emilio Pozuelo Monfort wrote: > [ Adding debian-dak@ to Cc ] > > One solution which has been discussed in the past is to import a full copy > > of stable towards stable-security at the beginning of each release cycle, > > but that is currently not possible

Re: Security releases for ecosystems that use static linking

2024-03-18 Thread Ola Lundqvist
Hi Emilio Yes, looks like it solves the problem as well. // Ola On Mon, 18 Mar 2024 at 13:14, Emilio Pozuelo Monfort wrote: > [ Adding debian-dak@ to Cc ] > > On 22/12/2023 09:54, Moritz Muehlenhoff wrote: > > On Thu, Dec 21, 2023 at 07:30:51PM -0300, Santiago Ruano Rincón wrote: > >> So let m

Re: Security releases for ecosystems that use static linking

2024-03-18 Thread Emilio Pozuelo Monfort
[ Adding debian-dak@ to Cc ] On 22/12/2023 09:54, Moritz Muehlenhoff wrote: On Thu, Dec 21, 2023 at 07:30:51PM -0300, Santiago Ruano Rincón wrote: So let me ask you: are you interested in addressing the infrastructure limitations to handle those kind of packages? and having some help for that?

Re: Security releases for ecosystems that use static linking

2023-12-22 Thread Santiago Ruano Rincón
El 22/12/23 a las 14:21, Moritz Muehlenhoff escribió: > On Fri, Dec 22, 2023 at 10:19:15AM -0300, Santiago Ruano Rincón wrote: > > El 22/12/23 a las 09:54, Moritz Muehlenhoff escribió: > > > On Thu, Dec 21, 2023 at 07:30:51PM -0300, Santiago Ruano Rincón wrote: > > > > So let me ask you: are you in

Re: Security releases for ecosystems that use static linking

2023-12-22 Thread Moritz Muehlenhoff
On Fri, Dec 22, 2023 at 10:19:15AM -0300, Santiago Ruano Rincón wrote: > El 22/12/23 a las 09:54, Moritz Muehlenhoff escribió: > > On Thu, Dec 21, 2023 at 07:30:51PM -0300, Santiago Ruano Rincón wrote: > > > So let me ask you: are you interested in addressing the infrastructure > > > limitations to

Re: Security releases for ecosystems that use static linking

2023-12-22 Thread Santiago Ruano Rincón
El 22/12/23 a las 09:54, Moritz Muehlenhoff escribió: > On Thu, Dec 21, 2023 at 07:30:51PM -0300, Santiago Ruano Rincón wrote: > > So let me ask you: are you interested in addressing the infrastructure > > limitations to handle those kind of packages? and having some help for > > that? > > Foremos

Re: Security releases for ecosystems that use static linking

2023-12-22 Thread Moritz Muehlenhoff
On Thu, Dec 21, 2023 at 07:30:51PM -0300, Santiago Ruano Rincón wrote: > So let me ask you: are you interested in addressing the infrastructure > limitations to handle those kind of packages? and having some help for > that? Foremost this is an infrastructure limitation that needs to be resolved:

Security releases for ecosystems that use static linking

2023-12-21 Thread Santiago Ruano Rincón
Dear Security, Release and Wanna-build teams, As some of you may be aware, we (the LTS Team) are reviewing the packages with limitations in their support, and I would like to bring some discussion regarding Go, Rust and the like. As the bookworm (and older) release notes document: The Debian