Re: CVE's and older versions of software

2022-02-17 Thread Dan Horák
On Thu, 17 Feb 2022 10:26:54 -0500 "Steven A. Falco" wrote: > On 2/17/22 09:58 AM, Ben Beasley wrote: > > This is covered by the Updates Policy[1]. There is quite a bit written > > there about why an incompatible update might or might not be allowed in a > > stable release. It also

Re: CVE's and older versions of software

2022-02-17 Thread Steven A. Falco
On 2/17/22 09:58 AM, Ben Beasley wrote: This is covered by the Updates Policy[1]. There is quite a bit written there about why an incompatible update might or might not be allowed in a stable release. It also specifically addresses security updates[2], and describes how you can petition FESCo

Re: CVE's and older versions of software

2022-02-17 Thread Ben Beasley
This is covered by the Updates Policy[1]. There is quite a bit written there about why an incompatible update might or might not be allowed in a stable release. It also specifically addresses security updates[2], and describes how you can petition FESCo for an exception, either for a

Re: CVE's and older versions of software

2022-02-17 Thread Steven A. Falco
On 2/17/22 06:46 AM, Stephen Snow wrote: On Wed, 2022-02-16 at 22:50 -0500, Demi Marie Obenour wrote: On 2/16/22 18:05, Adam Williamson wrote: On Wed, 2022-02-16 at 14:20 -0500, Steven A. Falco wrote: On 2/16/22 01:58 PM, Dan Horák wrote: On Wed, 16 Feb 2022 13:53:04 -0500 "Steven A. Falco"

Re: CVE's and older versions of software

2022-02-17 Thread Stephen Snow
On Wed, 2022-02-16 at 22:50 -0500, Demi Marie Obenour wrote: > On 2/16/22 18:05, Adam Williamson wrote: > > On Wed, 2022-02-16 at 14:20 -0500, Steven A. Falco wrote: > > > On 2/16/22 01:58 PM, Dan Horák wrote: > > > > On Wed, 16 Feb 2022 13:53:04 -0500 > > > > "Steven A. Falco" wrote: > > > > >

Re: CVE's and older versions of software

2022-02-16 Thread Demi Marie Obenour
On 2/16/22 18:05, Adam Williamson wrote: > On Wed, 2022-02-16 at 14:20 -0500, Steven A. Falco wrote: >> On 2/16/22 01:58 PM, Dan Horák wrote: >>> On Wed, 16 Feb 2022 13:53:04 -0500 >>> "Steven A. Falco" wrote: >>> There are some CVE's against KiCad that have been fixed in the latest

Re: CVE's and older versions of software

2022-02-16 Thread Adam Williamson
On Wed, 2022-02-16 at 14:20 -0500, Steven A. Falco wrote: > On 2/16/22 01:58 PM, Dan Horák wrote: > > On Wed, 16 Feb 2022 13:53:04 -0500 > > "Steven A. Falco" wrote: > > > > > There are some CVE's against KiCad that have been fixed in the latest > > > version, namely KiCad 6.0.2. I've built

Re: CVE's and older versions of software

2022-02-16 Thread Steven A. Falco
On 2/16/22 01:58 PM, Dan Horák wrote: On Wed, 16 Feb 2022 13:53:04 -0500 "Steven A. Falco" wrote: There are some CVE's against KiCad that have been fixed in the latest version, namely KiCad 6.0.2. I've built that for F36 and Rawhide. I have not released KiCad 6.0.2 into Fedora 34 and 35,

Re: CVE's and older versions of software

2022-02-16 Thread Dan Horák
On Wed, 16 Feb 2022 13:53:04 -0500 "Steven A. Falco" wrote: > There are some CVE's against KiCad that have been fixed in the latest > version, namely KiCad 6.0.2. I've built that for F36 and Rawhide. > > I have not released KiCad 6.0.2 into Fedora 34 and 35, because my > understanding is

CVE's and older versions of software

2022-02-16 Thread Steven A. Falco
There are some CVE's against KiCad that have been fixed in the latest version, namely KiCad 6.0.2. I've built that for F36 and Rawhide. I have not released KiCad 6.0.2 into Fedora 34 and 35, because my understanding is that by policy, we don't generally allow "major version" updates in stable