/srv/irclogs.ubuntu.com/2022/11/02/#ubuntu-security.txt

blahdeblah^00:20
ahasenackhi #security, when a package in a stable release is, say, 1.0-1, and you need to issue a security update, but that security update is just a rebuild13:41
ahasenackdo you call the rebuild 1.0-1build1, or something else?13:41
ahasenackthere is no added patch, so in principle it shouldn't warrant an ubuntu suffix13:41
mdeslaurahasenack: we could, but we usually don't14:08
ahasenackusually don't what?14:08
mdeslaurahasenack: our automated tooling just uses our usual security update "ubuntu" version string14:08
ahasenackoh, so you would call it 1.0-1ubuntu0.1?14:08
mdeslauryes, even if we could use "build"14:09
ahasenackok, but you wouldn't mind if we used 1.0-1build1?14:09
mdeslaurnope, wouldn't mind at all, though you probably want 1build0.1 just to be sure14:09
ahasenack(bar other upgrade issues that might arise, but let's assume I checked)14:09
ahasenackis there precedence for using 1build0.1?14:10
sdezielisn't using "build" risking to conflict with a fresher import from debian?14:10
mdeslaurwe do that so we don't collide with later releases that may have gotten a build1 during the dev cycle14:10
ahasenackbut it's a stable release, not devel14:11
ahasenackand later stable releases have a new upstream version14:11
mdeslaurso, in what I'm describing is for stable releases, not the dev release14:11
ahasenack(in this particular case)14:11
ahasenackok, let me layout the actual package14:11
mdeslaurahasenack: if you look at the publishing history, and there was never a build1, sure, you can use build114:11
ahasenackhttps://pastebin.ubuntu.com/p/69vJC7Bvdy/14:12
ahasenackwould you still prefer 1build0.1?14:12
mdeslaurok, looks like there was never a 1.0.5-1build1 https://launchpad.net/ubuntu/+source/go-md2man/+publishinghistory14:12
mdeslauryou can use build1 if you like14:13
mdeslaurusing 0.1 vs 1 is just to minimize the chance of colliding with the package history14:13
ahasenackk14:13
ahasenackit's even gone from devel14:14
ahasenackjammy even14:14
ahasenackk14:14
JanCsdeziel: imports from Debian are always rebuilds, so theoretically... shouldn't all buildN suffixes from Debian be dropped?  :)17:49

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!