[Secure-testing-team] Proposed syntax changes for CAN/list / finalization phase

Florian Weimer fw at deneb.enyo.de
Fri Sep 23 21:57:40 UTC 2005


* Moritz Muehlenhoff:

> CAN-2005-3011 (texindex in texinfo 4.7 and earlier allows local users to overwrite ...)
>         - texinfo unfixed (bug #328265; low)

Please use some characters which cannot be part of version numbers,
for example:

         - texinfo <unfixed> (bug #328265; low)

Also for not-affected, BTW.

Apart from that, I fully support this change.

>         - mediawiki itp (bug #276057; bug #217571)

Same here.  Also a good idea.

> Please review and let's finalize the format somehow.

Recently, it occurred to me that we have no good way to reference a
Debian bug which deals with a non-issue as far as we are concerned:

         - texinfo <not-affected> (we do not ship this particular shell script)

The usual space for bug references is taken by the free-form text.
For uniformity, I'd rather put this text into a NOTE: und go with the
standard syntax for bug references.

Apart from that, it probably makes sense to allow Debian bug numbers
in the { ... } cross-references (for issues which do not have package
notes, but still reference Debian bugs).




More information about the Secure-testing-team mailing list