Announcement

Collapse
No announcement yet.

What is the project's philosophy with regard to vulnerability management?

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    What is the project's philosophy with regard to vulnerability management?

    I'm working on a conference talk in which I will discuss the trade-offs inherent to long term releases.

    Specifically: distributing software for a longer period than it is maintained upstream is very labor intensive, and different long-term systems approach the problem in different ways. RHEL starts with Fedora but removes ~90% of the packages and features in order to reduce the labor costs over the life of a release. Ubuntu similarly starts with Debian but splits repositories into a small "main" repo component that they promise to maintain and a large "universe" component that they document as merely a snapshot for which they do not promise any updates. Debian is probably effectively similar to Ubuntu, but they don't divide their repo the same way so it's hard to make any clear statements about user expectation of patch coverage over the distribution.

    I am curious about how the maintainers of systems derived from Ubuntu LTS releases think about security risks and patch coverage.

    Are there any packages in "universe" that are used in a default installation of your desktop? Do you monitor those packages for new CVEs?

    Are there any packages in "universe" that you patch because your users would otherwise be at risk? Do you update those packages by backporting patches or by rebasing to new upstream releases?

    Do you provide guidance to users about the packages they install from the Ubuntu "universe" repo collection using apt?

    Do you recommend using software sources like Flatpak or Snap to give users access to application releases that are maintained and get security patches?

    Is there anything else that you want users to know about your approach to vulnerability remediation or related security topics?

    If this is not the best place to ask a question of the maintainers, where should I ask?




    #2
    The best place to ask is the developers directly. Matix is the best go-to, imo. Devs are not here lurking as much as we users are

    The kubuntu-devel room is the place to go. There are usually people around, and they are easy to talk with.

    The kubuntu-devel mailing list is another option, though this seems to be less active.
    Self-built: Asus PRIME B550M-K/Ryzen 5600GT/32Gb/Intel ARC B580 12Gb/KDE neon
    HP Elitedesk 800 G3 Mini: i5-7500T(35w)/32Gb/Kubuntu LTS
    HP Chromebook 14: i5-1135G7/8Gb/512Gb SSD/KDE Linux

    Comment

    Users Viewing This Topic

    Collapse

    There are 0 users viewing this topic.

    Working...
    X