Subject: Re: Automated security checks
To: Lubomir Sedlacik <salo@Xtrmntr.org>
From: =?UTF-8?B?TWFyaWphbiBVbmV0acSH?= <marijan.unetic@epta.hr>
List: netbsd-help
Date: 03/31/2005 15:03:00
Lubomir Sedlacik wrote:

>hi,
>
>On Thu, Mar 31, 2005 at 02:34:10PM +0200, Marijan Unetić wrote:
>  
>
>>I tried audit-packages and it reports some vulnerable programs.  Are
>>these packages patched in the meantime?  I have PKG?PATH set ot the
>>2004Q3.  Is this querter still maintained in respect to security
>>updates, and how long is it going to be.  My NetBSD is 2.0 i386.
>>    
>>
>
>2004Q3 is unmaintained and usupported for more than 3 months now.
>
>  
>
>>What is the best strategy for keeping system updated to security
>>patches, but stable.
>>    
>>
>
>always track the latest stable branch, which is created every quarter.
>the current stable branch is 2005Q1.  after branching a new stable
>branch the previous one becomes unsupported.
>
>
>regards,
>
>  
>
I read Packages.txt and netbsd.pdf guides, but I still don't understand
general methods.

Is there a migrattion procedure to 2005Q1 (which command should be issued,
to update all necessary files)?
What about pkgsrc tree, should it be dowloaded manually?
If so, which file is synced with 2005Q1?

Is it possible to automate this procedures and control it somehow?
I can't use CVS since I can't ssh across firewall.

Marijan