Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 18 Apr 2022 12:57:12 -0700
From:      Kevin Oberman <rkoberman@gmail.com>
To:        freebsd-security@freebsd.org
Subject:   Lack of notification of security notices
Message-ID:  <CAN6yY1tcGowuUPG0TGBvLuVZzm_inRt77yp7efpvU3JWHk2Dcg@mail.gmail.com>

next in thread | raw e-mail | index | archive | help
--0000000000003c961505dcf32e43
Content-Type: text/plain; charset="UTF-8"

As per the FreeBSD Security Information web page
<https://www.freebsd.org/security/>, security notifications are sent to:

   -

   FreeBSD-security-notifications@FreeBSD.org
   -

   FreeBSD-security@FreeBSD.org
   -

   FreeBSD-announce@FreeBSD.org

This policy has lately been ignored. No postings show up in the archives of
FreeBSD-security-notifications@FreeBSD.org since January. Likewise for
freebsd-announce. The only list showing the April 6 announcements is this
one, freebsd-security@freebad.org.

In the past, Security Announcements and Errata Notes have also been copied
to the stable and current lists as appropriate, although this is not
mentioned.  This delayed the update of my systems by several days.
Fortunately, only one of these vulnerabilities was relevant to my systems.

Even though the announcements are almost 2 weeks old, it is still likely
that some people are unaware of them, so I would strongly urge that they be
posted to, at least, FreeBSD-Announce and  FreeBSD-Stable lists.

In passing, I will note  that the same issue appears to be occurring with
posts of Errata Notices.
-- 
Kevin Oberman, Part time kid herder and retired Network Engineer
E-mail: rkoberman@gmail.com
PGP Fingerprint: D03FB98AFA78E3B78C1694B318AB39EF1B055683

--0000000000003c961505dcf32e43
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_default" style=3D"font-family:tahoma,s=
ans-serif;font-size:small"><div class=3D"gmail_default" style=3D"font-famil=
y:tahoma,sans-serif;font-size:small">As per the <a href=3D"https://www.free=
bsd.org/security/" target=3D"_blank">FreeBSD Security Information web page<=
/a>, security notifications are sent to:</div><div class=3D"gmail_default" =
style=3D"font-family:tahoma,sans-serif;font-size:small"><div>
<ul><li>
<p><a href=3D"mailto:FreeBSD-security-notifications@FreeBSD.org" target=3D"=
_blank">FreeBSD-security-notifications@FreeBSD.org</a></p>
</li><li>
<p><a href=3D"mailto:FreeBSD-security@FreeBSD.org" target=3D"_blank">FreeBS=
D-security@FreeBSD.org</a></p>
</li><li>
<p><a href=3D"mailto:FreeBSD-announce@FreeBSD.org" target=3D"_blank">FreeBS=
D-announce@FreeBSD.org</a></p>
</li></ul>
</div></div><div style=3D"font-family:tahoma,sans-serif;font-size:small" cl=
ass=3D"gmail_default">This policy has lately been ignored. No postings show=
 up in the archives of <a href=3D"mailto:FreeBSD-security-notifications@Fre=
eBSD.org" target=3D"_blank">FreeBSD-security-notifications@FreeBSD.org</a> =
since January. Likewise for freebsd-announce. The only list showing the Apr=
il 6 announcements is this one, <a href=3D"mailto:freebsd-security@freebad.=
org" target=3D"_blank">freebsd-security@freebad.org</a>.</div><div style=3D=
"font-family:tahoma,sans-serif;font-size:small" class=3D"gmail_default"><br=
></div><div style=3D"font-family:tahoma,sans-serif;font-size:small" class=
=3D"gmail_default">In
 the past, Security Announcements and Errata Notes have also been copied
 to the stable and current lists as appropriate, although this is not menti=
oned.=C2=A0 This=20
delayed the update of my systems by several days. Fortunately, only one=20
of these vulnerabilities was relevant to my systems.<br></div><div style=3D=
"font-family:tahoma,sans-serif;font-size:small" class=3D"gmail_default"><br=
></div><div style=3D"font-family:tahoma,sans-serif;font-size:small" class=
=3D"gmail_default">Even
 though the announcements are almost 2 weeks old, it is still likely=20
that some people are unaware of them, so I would strongly urge that
 they be posted to, at least, FreeBSD-Announce and=C2=A0 FreeBSD-Stable=20
lists.</div><div style=3D"font-family:tahoma,sans-serif;font-size:small" cl=
ass=3D"gmail_default"><br></div><div style=3D"font-family:tahoma,sans-serif=
;font-size:small" class=3D"gmail_default">In passing, I will note=C2=A0 tha=
t the same issue appears to be occurring with posts of Errata Notices.<font=
 color=3D"#888888"><br></font></div><font color=3D"#888888"></font></div>--=
 <br><div dir=3D"ltr" class=3D"gmail_signature" data-smartmail=3D"gmail_sig=
nature"><div dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div><=
div dir=3D"ltr">Kevin Oberman, Part time kid herder and retired Network Eng=
ineer<br>E-mail: <a href=3D"mailto:rkoberman@gmail.com" target=3D"_blank">r=
koberman@gmail.com</a><br></div><div>PGP Fingerprint: D03FB98AFA78E3B78C169=
4B318AB39EF1B055683</div></div></div></div></div></div></div></div></div>

--0000000000003c961505dcf32e43--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?CAN6yY1tcGowuUPG0TGBvLuVZzm_inRt77yp7efpvU3JWHk2Dcg>