Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.security > #6405

Re: security-tracker: A proposal to significantly reduce reported false-positives (no affected-code shipped)

Path csiph.com!weretis.net!feeder8.news.weretis.net!news.samoylyk.net!gothmog.csi.it!bofh.it!news.nic.it!robomod
From Samuel Henrique <samueloph@debian.org>
Newsgroups linux.debian.security
Subject Re: security-tracker: A proposal to significantly reduce reported false-positives (no affected-code shipped)
Date Sun, 13 Apr 2025 17:30:02 +0200
Message-ID <KB7rs-dfDl-29@gated-at.bofh.it> (permalink)
References <KlYq6-390b-5@gated-at.bofh.it>
X-Original-To Debian Security Team <team@security.debian.org>, debian-security@lists.debian.org, Emilio Pozuelo Monfort <pochu@debian.org>, Moritz Mühlenhoff <jmm@inutil.org>
X-Mailbox-Line From debian-security-request@lists.debian.org Sun Apr 13 15:24:09 2025
Old-Return-Path <samueloph@debian.org>
X-Amavis-Spam-Status No, score=-108.328 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, DKIMWL_WL_HIGH=-0.438, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, LDO_WHITELIST=-5, RCVD_IN_DNSWL_MED=-2.3, SARE_MSGID_LONG45=0.893, SARE_MSGID_LONG50=0.726, UNPARSEABLE_RELAY=0.001, USER_IN_DKIM_WELCOMELIST=-0.01, USER_IN_DKIM_WHITELIST=-100] autolearn=ham autolearn_force=no
MIME-Version 1.0
Content-Type text/plain; charset=us-ascii
Content-Disposition inline
X-Debian-User samueloph
X-Mailing-List <debian-security@lists.debian.org> archive/latest/29602
List-ID <debian-security.lists.debian.org>
List-URL <https://lists.debian.org/debian-security/>
List-Archive https://lists.debian.org/msgid-search/ex5wntkdvkihjwinbzwj33iewloaerbtaft5upczp6bhv4vu5j@ir4yvvm5n66e
Approved robomod@news.nic.it
Lines 21
Organization linux.* mail to news gateway
Sender robomod@news.nic.it
X-Original-Date Sun, 13 Apr 2025 16:06:38 +0100
X-Original-Message-ID <ex5wntkdvkihjwinbzwj33iewloaerbtaft5upczp6bhv4vu5j@ir4yvvm5n66e>
X-Original-References <yxe42tm2aahlo7zkmb5fga5j3i72bc47rd445hibiewbadgpvw@erxyp5lgfirp>
Xref csiph.com linux.debian.security:6405

Show key headers only | View raw


Hello everyone,

On Sun, 2 Mar 2025 at 20:26, Samuel Henrique <samueloph@debian.org> wrote:
> Just checking if you would have time to look into this.

Sending another ping, this proposal is now 1 year old.

For clarity, I'm not requesting the team to do any work here. I can work on the
changes, I just need a decision on the solution.

Personally, I have it as a high priority to cut down those 20% false-positive
CVEs reported for Debian containers, since a lot of official containers are
based on us, but this will also help non-container users.

I'm hoping that sending this is fine, but let me know if I should have waited
more than a month from the previous message.

Regards,

--
Samuel Henrique <samueloph>

Back to linux.debian.security | Previous | NextPrevious in thread | Next in thread | Find similar


Thread

Re: security-tracker: A proposal to significantly reduce reported  false-positives (no affected-code shipped) Samuel Henrique <samueloph@debian.org> - 2024-11-28 00:50 +0100
  Re: security-tracker: A proposal to significantly reduce reported  false-positives (no affected-code shipped) Salvatore Bonaccorso <carnil@debian.org> - 2024-12-01 15:10 +0100
    Re: security-tracker: A proposal to significantly reduce reported  false-positives (no affected-code shipped) Samuel Henrique <samueloph@debian.org> - 2025-03-02 21:50 +0100
      Re: security-tracker: A proposal to significantly reduce reported  false-positives (no affected-code shipped) Samuel Henrique <samueloph@debian.org> - 2025-04-13 17:30 +0200
        Re: security-tracker: A proposal to significantly reduce reported  false-positives (no affected-code shipped) Salvatore Bonaccorso <carnil@debian.org> - 2025-04-13 17:40 +0200
      Re: security-tracker: A proposal to significantly reduce reported  false-positives (no affected-code shipped) Samuel Henrique <samueloph@debian.org> - 2025-04-13 18:10 +0200
        Re: security-tracker: A proposal to significantly reduce reported  false-positives (no affected-code shipped) Salvatore Bonaccorso <carnil@debian.org> - 2025-05-01 11:30 +0200
          Re: security-tracker: A proposal to significantly reduce reported  false-positives (no affected-code shipped) Samuel Henrique <samueloph@debian.org> - 2025-05-10 21:40 +0200
            Re: security-tracker: A proposal to significantly reduce reported  false-positives (no affected-code shipped) Santiago Ruano Rincón <santiagorr@riseup.net> - 2025-05-16 20:30 +0200
              Re: security-tracker: A proposal to significantly reduce reported  false-positives (no affected-code shipped) Salvatore Bonaccorso <carnil@debian.org> - 2025-05-18 18:50 +0200
                Re: security-tracker: A proposal to significantly reduce reported  false-positives (no affected-code shipped) Roberto C. Sánchez <roberto@debian.org> - 2025-06-03 23:30 +0200

csiph-web