|
|
|
|
|
by vlovich123
568 days ago
|
|
These two statements to me seem contradictory: > QEMU has historically not made particularly timely security fixes either on mainline or on branches > It's much easier for us to stick to making source releases, and delegate the job of providing binaries to our downstreams Am I correct that this is essentially saying "we're going to do a snapshot of the software periodically but end users are responsible for applying patches that are maintained by other users as part of building"? Where do these security patches come from and how do non-Debian distros pick them up? Are Arch maintainers in constant contact with Debian maintainers for security issues to know to apply those patches & rebuild? |
|
[1] and also to stable branches, but not day-of-cve-announcement level of urgency.