GNU bug report logs - #25852
Users not updating their installations of Guix

Previous Next

Package: guix;

Reported by: Leo Famulari <leo <at> famulari.name>

Date: Thu, 23 Feb 2017 21:13:02 UTC

Severity: important

Done: ludo <at> gnu.org (Ludovic Courtès)

Bug is archived. No further changes may be made.

Full log


View this message in rfc822 format

From: Mark H Weaver <mhw <at> netris.org>
To: ludo <at> gnu.org (Ludovic Courtès)
Cc: 25852 <at> debbugs.gnu.org, Leo Famulari <leo <at> famulari.name>
Subject: bug#25852: Users not updating their installations of Guix
Date: Fri, 10 Mar 2017 20:48:24 -0500
ludo <at> gnu.org (Ludovic Courtès) writes:

> Mark H Weaver <mhw <at> netris.org> skribis:
>
>> We could simply issue a warning if the version of guix currently in use
>> is more than N hours old, on the assumption that after N hours it's
>> likely to be stale.  The default value of N might be in the range 48-96
>> (2-4 days).  A quick perusal through the recent commit log on our master
>> branch indicates that it's quite rare for 4 days to pass without a
>> security update.
>>
>> What do you think?
>
> That sounds like an easy and reasonable approach.
>
> I wonder what would be the best place to emit this warning.  Upon ‘guix
> package -i’ maybe?

Also "guix package -u" and the "guix system" commands that build
systems.  I suspect that many users run "guix pull" as their normal
users but never think to run it as root.

     Mark




This bug report was last modified 8 years and 15 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.