PDA

View Full Version : Backports and security updates


WW
October 18th, 2005, 07:33 AM
How are security updates integrated with backports?

(Sorry if this is in a FAQ somewhere. I didn't find anything in my forum search.)

geearf
October 18th, 2005, 02:42 PM
I guess by the version tag first you''ll get one, and if the version of the other is greater, then you'l get it and so on ..

A security patch to a specific ubuntu program should not work well if you have a backport version, but usually you will get the file rather than the diff I think.

WW
October 18th, 2005, 10:12 PM
I guess a more specific question is this: Are the people who are maintaining the backports also updating the backports when security vulnerabilities are discovered?

Seth
October 18th, 2005, 10:51 PM
Methinks not.

duffman25
October 19th, 2005, 10:20 AM
Methinks not.
I think "sometimes". If a backport package has a vulnerability discovered, then a new upstream fix will enter the current development branch. This new package will likely be backported again, so there you have the new version of the package with the security fix + some updates. I'm correct? This is only true if the backport team backport every new version of the already backported packages.

duffman25
October 19th, 2005, 10:22 AM
I think "sometimes". If a backport package has a vulnerability discovered, then a new upstream fix will enter the current development branch. This new package will likely be backported again, so there you have the new version of the package with the security fix + some updates. I'm correct? This is only true if the backport team backport every new version of the already backported packages.

That last line sound like a tongue-twister. ;)