6 ms·
Unfortunately, Debian testing doesn't get security updates.
by pm7 7y ago
Unfortunately, Debian testing doesn't get security updates.
- rollerrrr 7y agoTo the best of my knowledge, this is not true. Have a link?
- deleted 7y ago[deleted]
- pm7 7y agoSee this comment: https://news.ycombinator.com/item?id=21492080 https://news.ycombinator.com/item?id=21492080 Also, this: https://www.debian.org/security/faq.en.html#testing https://www.debian.org/security/faq.en.html#testing > there is a minimum two-day migration delay
- hollerith 7y agoGood to know. From https://wiki.debian.org/Status/Testing https://wiki.debian.org/Status/Testing, here is some more detail: >there is security support for testing, but in general it cannot be expected to be of the same quality as for stable: >Updates for testing-security usually get less testing than updates for stable-security. >Updates for embargoed issues take longer because the testing security team does not have access to embargoed information. >Testing is changing all the time which increases the likelyhood of problems with the build infrastructure. Such problems can delay security updates in testing.
- tuldia 7y agoOne can think of Debian testing as the "next-stable". How does it works? 1. Upstream release a new version, it goes to unstable. 2. Package is tested for some days in unstable and get promoted to testing. So telling that testing doesn't get security updates is somewhat incorrect, since you are grabing recent software. But by the other hand having too recent software also has its downside ;)
- pm7 7y agoI simplified a bit. Yes, Debian testing gets new updates, which means it gets security updates. Eventually. It can (and does) take days for critical security updates to migrate from unstable to testing after stable has access to patched version. https://www.debian.org/security/faq.en.html#testing https://www.debian.org/security/faq.en.html#testing > there is a minimum two-day migration delay
- tuldia 7y ago> It can (and does) take days for critical security updates to migrate from unstable to testing after stable has access to patched version. Now you are making way to many assumptions with this phrase. Do you really think that make sense to have critical security updates for stable having to pass through the normal release cycle? :)
- pm7 7y agoI'm sorry, was my message unclear? There were no assumptions. I'm speaking from experience that when I was using Debian testing I would usually receive security updates days after they are available for Debian stable. Obviously security updates for stable do not go through normal release cycle. I wasn't commenting stable security updates, but lack of timely access to security updates on testing.