View previous topic :: View next topic |
Author |
Message |
Ferociouspineapple n00b
![n00b n00b](/images/ranks/rank_rect_0.gif)
Joined: 09 Feb 2023 Posts: 7
|
Posted: Sat Sep 16, 2023 9:16 pm Post subject: How does one stay abreast with vulnerabilities on a world... |
|
|
what's an effective way to stay abreast with vulnerabilities on a world file and dependencies basis without having to 'emerge -uD world' everyday?
While a cron job for glsa-check is a prospect, no GLSA seems to have been filed as so far for 914010 libwebp-1.3.1_p20230908 and the vulnerability for libwebp before that...at least from what I'm seeing [nothing from glsa-check after emerge --sync nor am I able to find it in the GLSA rss feed: https://security.gentoo.org/glsa/feed.rss]. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
sam_ Developer
![Developer Developer](/images/ranks/rank-dev.gif)
![](images/avatars/7738740495f7d1acc45bdb.jpg)
Joined: 14 Aug 2020 Posts: 2130
|
Posted: Sun Sep 17, 2023 2:23 am Post subject: |
|
|
We'd like to do GLSAs more and we're trying to, but the priority is generally getting a fixed version into tree which takes enough effort as it is.
I just suggest regular glsa-check and updating at least once a week. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
|