end-of-life template: Explicitly mention no more security announcements #10951

Merged
jnsamyak merged 2 commits from main into main 2026-06-08 03:11:06 +00:00
Contributor

The current template mentions that no more updates will be provided
for EOL Fedora releases.

This could create the (wrong) impression that the code is still evaluated
for security risks and that just the updates won't happen anymore.

To avoid any misunderstandings:
Add an explicit statement that also no more security announcements will
be made.

Signed-off-by: Manfred Spraul manfred@colorfullife.com

The current template mentions that no more updates will be provided for EOL Fedora releases. This could create the (wrong) impression that the code is still evaluated for security risks and that just the updates won't happen anymore. To avoid any misunderstandings: Add an explicit statement that also no more security announcements will be made. Signed-off-by: Manfred Spraul <manfred@colorfullife.com>
Owner

Fair enough. How about "No more updates of any kind, including security... "?

The any kind would then cover anything else people think might still happen?

Fair enough. How about "No more updates of any kind, including security... "? The any kind would then cover anything else people think might still happen?
Author
Contributor

Hi Kevin,

On 8/9/22 00:47, Kevin Fenzi wrote:

kevin commented on the pull-request: end-of-life template: Explicitly mention no more security announcements that you are following:
``
Fair enough. How about "No more updates of any kind, including security... "?

The any kind would then cover anything else people think might still happen?

The core message should be that all activity will be stopped. No more
package update, but also no more assessments for vulnerabilities, or
anything else.

Thus the fact that e.g. https://www.opencve.io/cve/CVE-2021-44228 lists
only cpe:2.3fedoraproject:fedora:34:::::::* and
cpe:2.3fedoraproject:fedora:35:::::::* must not be interpreted
as "Fedora 33 is not affected".

What would be your wording proposal?

Perhaps, as idea: We could use a positive sentence:

All activities related to Fedora N will be stopped after the said
date. This includes package updates and security assessments.

All the updates of Fedora N being pushed to stable will be stopped as
well.

--

    Manfred

Hi Kevin, On 8/9/22 00:47, Kevin Fenzi wrote: > kevin commented on the pull-request: `end-of-life template: Explicitly mention no more security announcements` that you are following: > `` > Fair enough. How about "No more updates of any kind, including security... "? > > The any kind would then cover anything else people think might still happen? The core message should be that all activity will be stopped. No more package update, but also no more assessments for vulnerabilities, or anything else. Thus the fact that e.g. https://www.opencve.io/cve/CVE-2021-44228 lists only cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* and cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* must not be interpreted as "Fedora 33 is not affected". What would be your wording proposal? Perhaps, as idea: We could use a positive sentence: > All activities related to Fedora N will be stopped after the said > date. This includes package updates and security assessments. > > All the updates of Fedora N being pushed to stable will be stopped as > well. --     Manfred
Owner

Well, the reason I proposed adding "of any kind" is that if we say "no security updates" someone might assume there still were bugfix and enhancement updates.

So, my proposal was your changes with adding "of any kind".

Perhaps @bcotton could have some further ideas?

Well, the reason I proposed adding "of any kind" is that if we say "no security updates" someone might assume there still were bugfix and enhancement updates. So, my proposal was your changes with adding "of any kind". Perhaps @bcotton could have some further ideas?
Contributor

I think the proposed text with Kevin's addition is good. I was originally going to push back against the "or security updates", but reading Manfred's reasoning in the comments, I think it makes sense. Adding "of any kind" is redundant, but it's a good redundancy in this case. We want to make it very clear that "this is all you get", so a belt-and-suspenders approach makes sense here.

I think the proposed text with Kevin's addition is good. I was originally going to push back against the "or security updates", but reading Manfred's reasoning in the comments, I think it makes sense. Adding "of any kind" is redundant, but it's a good redundancy in this case. We want to make it very clear that "this is all you get", so a belt-and-suspenders approach makes sense here.
Author
Contributor

Hi,

On 8/15/22 16:00, Ben Cotton wrote:

bcotton commented on the pull-request: end-of-life template: Explicitly mention no more security announcements that you are following:
I think the proposed text with Kevin's addition is good. I was originally going to push back against the "or security updates", but reading Manfred's reasoning in the comments, I think it makes sense. Adding "of any kind" is redundant, but it's a good redundancy in this case. We want to make it very clear that "this is all you get", so a belt-and-suspenders approach makes sense here.

To reply, visit the link below or just reply to this email
https://pagure.io/releng/pull-request/10951

Updated patch is attached.

--

    Manfred

Hi, On 8/15/22 16:00, Ben Cotton wrote: > bcotton commented on the pull-request: `end-of-life template: Explicitly mention no more security announcements` that you are following: > `` > I think the proposed text with Kevin's addition is good. I was originally going to push back against the "or security updates", but reading Manfred's reasoning in the comments, I think it makes sense. Adding "of any kind" is redundant, but it's a good redundancy in this case. We want to make it very clear that "this is all you get", so a belt-and-suspenders approach makes sense here. > `` > > To reply, visit the link below or just reply to this email > https://pagure.io/releng/pull-request/10951 Updated patch is attached. --     Manfred
Author
Contributor

2 new commits added

  • end-of-life template: Explicitly mention no more security announcements
  • Revert "end-of-life template: Explicitly mention no more security announcements"
**2 new commits added** * ``end-of-life template: Explicitly mention no more security announcements`` * ``Revert "end-of-life template: Explicitly mention no more security announcements"``
Author
Contributor

Attachments didn't work.

Unfortunately I couldn't find how to update a PR, thus here is the
updated patch:

https://pagure.io/fork/manfredcolorfu/releng/c/69ab47f2774a24119ff3c1c4a7d71a3900e63f6b?branch=main

--

    Manfred

Attachments didn't work. Unfortunately I couldn't find how to update a PR, thus here is the updated patch: https://pagure.io/fork/manfredcolorfu/releng/c/69ab47f2774a24119ff3c1c4a7d71a3900e63f6b?branch=main --     Manfred
Author
Contributor

1 new commit added

  • Revert "end-of-life template: Explicitly mention no more security announcements"
**1 new commit added** * ``Revert "end-of-life template: Explicitly mention no more security announcements"``
Contributor

LGTM, although we might want to take this opportunity to say Fedora Linux instead of Fedora:

https://communityblog.fedoraproject.org/fedora-is-a-community-fedora-linux-is-our-os/

LGTM, although we might want to take this opportunity to say Fedora Linux instead of Fedora: https://communityblog.fedoraproject.org/fedora-is-a-community-fedora-linux-is-our-os/
Owner

Now there's conflicts. ;(

You can update the pr by getting the branch the way you want it locally and then git push --force it. It should update the PR.

Now there's conflicts. ;( You can update the pr by getting the branch the way you want it locally and then git push --force it. It should update the PR.
Author
Contributor

3 new commits added

  • end-of-life template: Explicitly mention no more security announcements
  • Revert "end-of-life template: Explicitly mention no more security announcements"
  • end-of-life template: Explicitly mention no more security announcements
**3 new commits added** * ``end-of-life template: Explicitly mention no more security announcements`` * ``Revert "end-of-life template: Explicitly mention no more security announcements"`` * ``end-of-life template: Explicitly mention no more security announcements``
Author
Contributor

rebased onto 6e27edaeb71d7afb3c317c302042b1b33d142375

rebased onto 6e27edaeb71d7afb3c317c302042b1b33d142375
Author
Contributor

1 new commit added

  • mail-templates: Update for Fedora Linux instead of Fedora
**1 new commit added** * ``mail-templates: Update for Fedora Linux instead of Fedora``
Author
Contributor

Hi Kevin,
On 8/29/22 21:59, Kevin Fenzi wrote:

kevin commented on the pull-request: end-of-life template: Explicitly mention no more security announcements that you are following:
``
Now there's conflicts. ;(

Now better?

Open are:

  • sometimes, there is a space before a cross reference, sometimes no space:

   "schedule[1]" and "activation point [2]"

  • The date format is mixed: "YYYY-MM-DD", "MMM DD, YYYY" and "MMM DD YYYY"

  • I've replaced the "37" in 01-mass-rebuild-start.txt with N. I do not
    know if this was right.

You can update the pr by getting the branch the way you want it locally and then git push --force it. It should update the PR.

``

To reply, visit the link below or just reply to this email
https://pagure.io/releng/pull-request/10951

Hi Kevin, On 8/29/22 21:59, Kevin Fenzi wrote: > kevin commented on the pull-request: `end-of-life template: Explicitly mention no more security announcements` that you are following: > `` > Now there's conflicts. ;( Now better? Open are: - sometimes, there is a space before a cross reference, sometimes no space:    "schedule[1]" and "activation point [2]" - The date format is mixed: "YYYY-MM-DD", "MMM DD, YYYY" and "MMM DD YYYY" - I've replaced the "37" in 01-mass-rebuild-start.txt with N. I do not know if this was right. > You can update the pr by getting the branch the way you want it locally and then git push --force it. It should update the PR. > > `` > > To reply, visit the link below or just reply to this email > https://pagure.io/releng/pull-request/10951
Owner

I'd say always use a space for references.

date format should be YYYY-MM-DD everywhere.

Replace 37 with 'fN' :)

Can you make those changes and rebase?

I'd say always use a space for references. date format should be YYYY-MM-DD everywhere. Replace 37 with 'fN' :) Can you make those changes and rebase?
Author
Contributor

rebased onto d9d319ab91

rebased onto d9d319ab9169c57b53aded2d246dd8947ad781ec
Author
Contributor

2 new commits added

  • mail-templates: Update for Fedora Linux instead of Fedora, spellings
  • end-of-life template: Explicitly mention no more security announcements
**2 new commits added** * ``mail-templates: Update for Fedora Linux instead of Fedora, spellings`` * ``end-of-life template: Explicitly mention no more security announcements``
Author
Contributor

Changes and rebase done.
As additional finding: in 07, the references started with [0], in the rest, the references started with [1]. I've changed it to [1] for all files.

Changes and rebase done. As additional finding: in 07, the references started with [0], in the rest, the references started with [1]. I've changed it to [1] for all files.
Owner

Great! Looks ok to me now. Many thanks for the work on it...

Great! Looks ok to me now. Many thanks for the work on it...
Owner

Pull-Request has been merged by kevin

Pull-Request has been merged by kevin
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
3 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
releng/tickets!10951
No description provided.