end-of-life template: Explicitly mention no more security announcements #10951
No reviewers
Labels
No labels
after freeze
automation
backlog
blocked
change-ack
change-nak
change-noreleng
changes
Closed As
Can't Fix
Closed As
Duplicate
Closed As
Fixed
Closed As
Fixed with Explanation
Closed As
Get back later
Closed As
Grooming
Closed As
Insufficient data
Closed As
Invalid
Closed As
It's all good
Closed As
taiga
Closed As
upstream
day-to-day
dev
docs
easyfix
epel
f26
f27
f28
f29
f30
f31
f32
f33
f34
f35
f36
f37
f38
f39
f40
f41
f42
f43
f44
f45
fedora
groomed
high-gain
high-trouble
in-progress
in-review
investigation
legal
low-gain
low-trouble
mass rebuild
medium-gain
medium-trouble
meeting
mini-initiative
new_artifact
ops
pdc_retirement
rawhide
RCA
review
script
sidetarget
sprint-0
sprint-1
sprint-2
sprint-3
sprint-4
sprint-5
unfrozen
waiting on external
Backlog Status
Needs Review
Backlog Status
Ready
chore
documentation
points
01
points
02
points
03
points
05
points
08
points
13
Priority
High
Priority
Low
Priority
Medium
Sprint Status
Blocked
Sprint Status
Done
Sprint Status
In Progress
Sprint Status
Review
Sprint Status
To Do
Technical Debt
Work Item
Bug
Work Item
Epic
Work Item
Spike
Work Item
Task
Work Item
User Story
No milestone
No project
No assignees
3 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
releng/tickets!10951
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "main"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The current template mentions that no more updates will be provided
for EOL Fedora releases.
This could create the (wrong) impression that the code is still evaluated
for security risks and that just the updates won't happen anymore.
To avoid any misunderstandings:
Add an explicit statement that also no more security announcements will
be made.
Signed-off-by: Manfred Spraul manfred@colorfullife.com
Fair enough. How about "No more updates of any kind, including security... "?
The any kind would then cover anything else people think might still happen?
Hi Kevin,
On 8/9/22 00:47, Kevin Fenzi wrote:
The core message should be that all activity will be stopped. No more
package update, but also no more assessments for vulnerabilities, or
anything else.
Thus the fact that e.g. https://www.opencve.io/cve/CVE-2021-44228 lists
only cpe:2.3⭕fedoraproject:fedora:34:::::::* and
cpe:2.3⭕fedoraproject:fedora:35:::::::* must not be interpreted
as "Fedora 33 is not affected".
What would be your wording proposal?
Perhaps, as idea: We could use a positive sentence:
--
Manfred
Well, the reason I proposed adding "of any kind" is that if we say "no security updates" someone might assume there still were bugfix and enhancement updates.
So, my proposal was your changes with adding "of any kind".
Perhaps @bcotton could have some further ideas?
I think the proposed text with Kevin's addition is good. I was originally going to push back against the "or security updates", but reading Manfred's reasoning in the comments, I think it makes sense. Adding "of any kind" is redundant, but it's a good redundancy in this case. We want to make it very clear that "this is all you get", so a belt-and-suspenders approach makes sense here.
Hi,
On 8/15/22 16:00, Ben Cotton wrote:
Updated patch is attached.
--
Manfred
2 new commits added
end-of-life template: Explicitly mention no more security announcementsRevert "end-of-life template: Explicitly mention no more security announcements"Attachments didn't work.
Unfortunately I couldn't find how to update a PR, thus here is the
updated patch:
https://pagure.io/fork/manfredcolorfu/releng/c/69ab47f2774a24119ff3c1c4a7d71a3900e63f6b?branch=main
--
Manfred
1 new commit added
Revert "end-of-life template: Explicitly mention no more security announcements"LGTM, although we might want to take this opportunity to say Fedora Linux instead of Fedora:
https://communityblog.fedoraproject.org/fedora-is-a-community-fedora-linux-is-our-os/
Now there's conflicts. ;(
You can update the pr by getting the branch the way you want it locally and then git push --force it. It should update the PR.
3 new commits added
end-of-life template: Explicitly mention no more security announcementsRevert "end-of-life template: Explicitly mention no more security announcements"end-of-life template: Explicitly mention no more security announcementsrebased onto 6e27edaeb71d7afb3c317c302042b1b33d142375
1 new commit added
mail-templates: Update for Fedora Linux instead of FedoraHi Kevin,
On 8/29/22 21:59, Kevin Fenzi wrote:
Now better?
Open are:
"schedule[1]" and "activation point [2]"
The date format is mixed: "YYYY-MM-DD", "MMM DD, YYYY" and "MMM DD YYYY"
I've replaced the "37" in 01-mass-rebuild-start.txt with N. I do not
know if this was right.
I'd say always use a space for references.
date format should be YYYY-MM-DD everywhere.
Replace 37 with 'fN' :)
Can you make those changes and rebase?
rebased onto
d9d319ab912 new commits added
mail-templates: Update for Fedora Linux instead of Fedora, spellingsend-of-life template: Explicitly mention no more security announcementsChanges and rebase done.
As additional finding: in 07, the references started with [0], in the rest, the references started with [1]. I've changed it to [1] for all files.
Great! Looks ok to me now. Many thanks for the work on it...
Pull-Request has been merged by kevin