[CentOS] CentOS 5 Security Updates

Thu Feb 24 20:35:30 UTC 2011
Johnny Hughes <johnny at centos.org>

On 02/24/2011 02:05 PM, Ian Murray wrote:
> 
> 
>>
>>> I  know the development team is furiously working to get 5.6 out the door
>>>  so I understand that there will be delays. However, it was my
>>>  understanding that "Critical" security updates and those that are
>>>  "remotely exploitable" would be pushed out ahead of 5.6.
>>
>> That is my  understanding, too. However, I see that the only "Critical"
>> one on your list  is java-1.6.0-sun. This is not included in  CentOS...
> 
> 
> As far as I understand this is a highly untrivial task and breaks the "binary 
> compatible" rule. Nevertheless, this was attempted one or two dot releases ago, 
> I think as an experiment as much as anything.
> 
> I am not sure how the CentOS team thought of that exercise, in hindsight. I 
> would be interested in knowing. From the explanation that Russ gave, it was a 
> mighty effort, as far as I remember.

The issue is that these are BUILT on top of 5.6 by upstream ... so they
have to be built on 5.6 from us too.

That is just how is just how it is ...

What we have done in the past, if a fix will run OK on 5.5 and 5.6, is
release the fix early.  But that caused issues and bugs the last time we
did it on some installs.

Regardless, I don't think 5.6 will be much longer.



-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 253 bytes
Desc: OpenPGP digital signature
URL: <http://lists.centos.org/pipermail/centos/attachments/20110224/c3b345d8/attachment-0003.sig>