Subject: Re: Automated security checks
To: Marijan =?iso-8859-2?Q?Uneti=E6?= <marijan.unetic@epta.hr>
From: Lubomir Sedlacik <salo@Xtrmntr.org>
List: netbsd-help
Date: 03/31/2005 14:37:43
--Q8a9NmTVi5AMeZ2v
Content-Type: text/plain; charset=iso-8859-2
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

hi,

On Thu, Mar 31, 2005 at 02:34:10PM +0200, Marijan Uneti=E6 wrote:
> I tried audit-packages and it reports some vulnerable programs.  Are
> these packages patched in the meantime?  I have PKG?PATH set ot the
> 2004Q3.  Is this querter still maintained in respect to security
> updates, and how long is it going to be.  My NetBSD is 2.0 i386.

2004Q3 is unmaintained and usupported for more than 3 months now.

> What is the best strategy for keeping system updated to security
> patches, but stable.

always track the latest stable branch, which is created every quarter.
the current stable branch is 2005Q1.  after branching a new stable
branch the previous one becomes unsupported.


regards,

--=20
-- Lubomir Sedlacik <salo@{NetBSD,Xtrmntr,silcnet}.org>   --

--Q8a9NmTVi5AMeZ2v
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (NetBSD)

iD8DBQFCS+8XiwjDDlS8cmMRAt5FAJ0WMh6pvpZlDUD98A89xmfHWrEPgwCeNnB+
VCJBsi2fsPMeD4gzLVC4yig=
=GrlO
-----END PGP SIGNATURE-----

--Q8a9NmTVi5AMeZ2v--