[Pkg-owncloud-maintainers] Owncloud / security support

Moritz Muehlenhoff jmm at inutil.org
Fri Aug 29 05:50:40 UTC 2014


On Thu, Aug 28, 2014 at 02:01:22PM -0400, David Prévot wrote:
> Hi Moritz,
> 
> Thanks for your quick reply.
> 
> Le 28/08/2014 12:27, Moritz Mühlenhoff a écrit :
> > On Wed, Aug 27, 2014 at 06:30:44PM -0400, David Prévot wrote:
> >> Le 25/03/2014 12:32, David Prévot a écrit :
> >>> Le 25/03/2014 11:41, Moritz Muehlenhoff a écrit :
> 
> > What about Zend Framework, IIRC it's also entangled into owncloud?
> 
> I intend to follow up on Zend Framework too (I’ve NMUed it twice already
> for security issues), and just made my intent clear in #759575.

I think you can be more aggressive here than waiting a month, the maintainer
is also MIA for fckeditor.
 
> > Could you add a README.Debian file which indicates this to users?
> 
> I’ve just added the following on top of the existing README.Debian, and
> will do the same for the php-sabre* packages that will be shipped in
> Jessie (“Jessie+1” will be replaced by the next stable codename once
> known), thanks in advance for any fix/improvement/review/remark if you
> have some:
> 
> > Security support
> > ----------------
> > 
> > Since upstream support of ownCloud 7 will end during Jessie’s lifetime,
> > security support will be provided on a best effort basis with upstream help. 
> > Eventually, this package may be removed from once Jessie+1 is released if the
> > security support becomes too complicated or time-consuming, so ownCloud users 
> > will be advised to upgrade their servers to the new stable release.

LGTM

Cheers,
        Moritz




More information about the Pkg-owncloud-maintainers mailing list