|
|
Log in / Subscribe / Register

Brief items

Security

Security quote of the week

In other words, I would argue that security for most open source projects (by number, at least) is a resource problem, not a persuasion problem. Their authors are not investing in engineering process improvement in large part because they don't have time to both do that and to do the work on their project that they find fun and that inspired them to release it as open source in the first place.

That implies that the solution to look for isn't a winning persuasive argument, but instead is a way to get the developer more resources, either by somehow getting them more time to work on their project or by making the cost of better engineering process substantially smaller than it is now. GitHub's automated pull requests for dependencies with security vulnerabilities is a good example of the latter.

Russ Allbery

Comments (2 posted)

Kernel development

Kernel release status

The 5.7 merge window is open; it can be expected to close on April 12. See this article for a summary of what was merged in the early days of the 5.7 development cycle.

Stable updates: 5.6.2 was released on April 2 with an important wireless networking regression fix; it was followed almost immediately by 5.5.15, 5.4.30, 4.19.114, 4.14.175, 4.9.218, and 4.4.218. Then, 5.6.3, 5.5.16, and 5.4.31 showed up on April 8.

Comments (none posted)

Distributions

LineageOS 17.1 released

LineageOS 17.1 is out. This release of the Android-based distribution once known as CyanogenMod includes a rebase onto the Android 10 release of the Android Open Source Project, improved theme support, support for on-screen fingerprint sensors, the ability to use biometric sensors to control access to apps, and more. "On the whole, we feel that the 17.1 branch has reached feature and stability parity with 16.0 and is ready for initial release. With 17.1 being the most recent and most actively developed branch, on April 1st, 2020 it will begin receiving nightly builds and 16.0 will be moved to weekly builds."

Comments (none posted)

Distribution quote of the week

For a start, it genuinely was the case back when a lot of these apps were written that you couldn't so easily go out and "buy one off the shelf", so to speak. But there's also the whole idea of dogfooding, and the ecosystem. Again there's a historical angle to this: it wasn't just for us but for the whole industry that it was more common to build stuff in-house than outsource absolutely everything besides your "core competency", as is the management fad these days. So for us to build our own infrastructure was kind of a proof-of-concept that Fedora *was* a suitable environment for *anyone* to do that: at least at the time we felt that there was value in demonstrating that Fedora provided an environment in which you *could* build and deploy and maintain and use, you know, calendaring systems! and authentication systems! and election apps! and so on and so forth.

I agree that this has fallen out of fashion to an extent, and the "let's just outsource everything that isn't actively building bits into OS images" mindset is in tune with Current Industry Thinking and there is a sustainable logic behind it. Personally I still think it comes with significant issues, though, because there were a lot of what management is pleased to call "intangibles" that went along with doing all that work. We had an awful lot of "in-house" knowledge about a whole range of stuff because we *did* build and maintain and deploy and support all of these bits.

Adam Williamson

Comments (none posted)

Development

Firefox 74.0.1

Firefox 74.0.1 has been released with two security fixes. CVE-2020-6819 is a use-after-free when running the nsDocShell destructor and CVE-2020-6820 is a use-after-free when handling a ReadableStream. In both cases there have been targeted attacks in the wild abusing these flaws. These issues have also been fixed in Firefox ESR 68.6.1.

Comments (none posted)

Firefox 75.0

Firefox 75.0 has been released. New features include improvements to the address bar, making search easier, all trusted Web PKI Certificate Authority certificates known to Mozilla will be cached locally, and Firefox is available as a Flatpak. See the release notes for more details.

Comments (8 posted)

Page editor: Jake Edge
Next page: Announcements>>


Copyright © 2020, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds