On 6/21/11 6:27 PM, Karanbir Singh wrote: > On 06/21/2011 11:48 PM, Les Mikesell wrote: >> make that choice, which is why I think the choice should be opt-out, not >> in. It may be a matter of faith one way or another, but I think there > > A vast majority of these updates are not Security related, they are the > BA / EA variety, and if there is a security issue - we can always push > those packages into the regular /5/updates/ repo. > > quite a few people run private repo store's and they might not even come > across any of the CR stuff; so major security issues *should* go into > the regular /5/updates in an either and/or with CR I'd expect it to be common for the kernels and probably glibc's included with a point release or soon thereafter to include security fixes. If you push those, you have the biggest risk of affecting everything else - so what's the point of isolating the rest? -- Les Mikesell lesmikesell at gmail.com