Le 18/11/2014 11:51, Raphael Hertzog a écrit :

> Thank you for this information but it's not really a satisfactory answer.

I understand your concerns and I'm not claiming that shipping vulnerable
libraries is a good thing. My answer was a factual evaluation of the
impact of this vulnerability on Debian, so people are at least informed
about the actual risks.


> Please send a call for help on debian-devel(-announce) if you are not able
> to do the basic work of keeping your packages up-to-date. Then the
> publicity team might relay your message further... and maybe you'll find
> some supplementary volunteers.

Updating packages is not always "basic" unfortunately, I wish it was though.


Attachment: signature.asc
Description: OpenPGP digital signature

__
This is the maintainer address of Debian's Java team
<http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-java-maintainers>. 
Please use
debian-j...@lists.debian.org for discussions and questions.

Reply via email to