From owner-freebsd-pkg@FreeBSD.ORG Mon Oct 20 16:42:06 2014 Return-Path: Delivered-To: freebsd-pkg@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id AB14680 for ; Mon, 20 Oct 2014 16:42:06 +0000 (UTC) Received: from mail.ultra-secure.de (mail.ultra-secure.de [88.198.178.88]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id ED8838E1 for ; Mon, 20 Oct 2014 16:42:05 +0000 (UTC) Received: (qmail 1978 invoked by uid 89); 20 Oct 2014 16:42:07 -0000 Received: from unknown (HELO ?192.168.1.200?) (rainer@ultra-secure.de@217.71.83.52) by mail.ultra-secure.de with ESMTPA; 20 Oct 2014 16:42:07 -0000 Content-Type: text/plain; charset=utf-8 Mime-Version: 1.0 (Mac OS X Mail 8.0 \(1990.1\)) Subject: Re: We need much better security updates for packages From: Rainer Duffner In-Reply-To: <821921413779379@web13m.yandex.ru> Date: Mon, 20 Oct 2014 18:41:54 +0200 Content-Transfer-Encoding: quoted-printable Message-Id: <06AEEDD6-E7A7-4FAC-9FE5-54D329D42C07@ultra-secure.de> References: <821921413779379@web13m.yandex.ru> To: Martin Hanson X-Mailer: Apple Mail (2.1990.1) Cc: "freebsd-pkg@freebsd.org" X-BeenThere: freebsd-pkg@freebsd.org X-Mailman-Version: 2.1.18-1 Precedence: list List-Id: Binary package management and package tools discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 20 Oct 2014 16:42:06 -0000 > Am 20.10.2014 um 06:29 schrieb Martin Hanson = : >=20 > Hi >=20 > This is a suggestion. >=20 > If "pkg" is going to be any good, meaning as a real replacement for > always compiling from ports, I think it is really important that we > move away from a fixed weekly build when important security upgrades > are pending. >=20 >=20 > Or this could even be automatized perhaps? >=20 I believe, the quarter-yearly =E2=80=9Ecuts=E2=80=9C of the ports-tree = are supposed to be that. I have no idea, however, how fast and plenty updates are coming to this = branch. I there a mailing-list only for commits to that particular branch? I don=E2=80=99t want mails with all commits to the whole ports-tree=E2=80=A6= . I run my own poudriere server and if I really need a security-update, I = copy the stuff over from my =E2=80=9Ecurrent=E2=80=9C tree that follows = head. Ideally, I would just need to run a svn update - but I=E2=80=99d like to = know in advance what has changed=E2=80=A6