gnome-system-monitor 2.17 has been compromised
Par Benoît Dejean le mercredi, 28 février 2007, 10:45 - GNOME - Lien permanent
Last night, Matthias Clasen and Shaun McCance helped me fix a gnome-doc-utils bug in gnome-system-monitor tarball. I then released gnome-system-monitor-2.17.93 because I am the maintainer.
Then, somebody, who owns a regular svn/ssh account, has commited without approval unreviewed content to gnome-system-monitor trunk. He also tagged the wrong way. And in the end, he released gnome-system-monitor-2.17.94. I don't know anything about this man. I've just got an email from him to tell what he has done. Update: he even created&closed a bug against system-monitor.
gnome-system-monitor 2.17.94 is not official and not trusted at all. DO NOT USE IT.
The following are unreviewed, not trusted and have unknown content :
- SVN tag
GNOME_SYSTEM_MONITOR_2_17_94and revision 1935, 1936, 1937 and 1938 - gnome-system-monitor 2.17.94 tarballs on the GNOME ftp server.
Today 28/02/2007, only the following are trusted and official :
- SVN tag
tags/GNOME_SYSTEM_MONITOR_2_17_93and revisions up to 1934 - gnome-system-monitor 2.17.93 tarballs on the GNOME ftp server.
Security infrastructure
It would be nice to be able to GPG-sign tarballs that are uploaded to the GNOME FTP server.
Commentaires
and here's the explanation:
http://mail.gnome.org/archives/rele...
"compromised" is a strong word. this isn't binary stuff that we're talking about, a diff shouldn't be that hard?
Autant sur le SVN, y a rien de particulier, autant dans le tarball ... Y en a pour une semaine à vérifier le m4 :/
If it were me I'd rather _thank_ mariano and kmaraas for fixing stuff that was obviously problematic in the "official" release.
Get a life. You screwed up and someone fixed it. You should be thankful.
Wow on se croirait sur une mailing list debian... Franchement sans te connaître et en lisant ça tu fais un peu "control freak" paranoiaque
Tout cela vient d'une stupide confusion dan la précipitation pour essayer d'avoir un module ok pour la release... Je trouve que le ton indigné est franchement exagéré. Il y a eu boulette, certes, mais ce n'est pas comme si un pirate avait fait une release malveillante...
Quand tu ne sais pas pas du tout qui est la personne, quand tu n'as reçu aucun mail d'approbation ni rien, c'est un problème. Moi je me lève le matin, je vois qu'une release a été faite pendant que la nuit, je n'ai aucune info dessus, j'agite le drapeau rouge.