Le Mon, 1 Feb 2010 22:21:03 +0100, Heiko Baums <lists@xxxxxxxxxxxxxxx> a écrit : > If a security bug is found it should be filed to and fixed by upstream > anyway. This is true, except sometimes upstream patching can take a while and it would be a good idea to warn users about the problem in the meantime so that they can take temporary measures. If there's a single thing that I miss about Arch security, it's Arch Sheriff : it basically did that. Maybe people who want to do something about security could begin with resurrecting it. -- catwell