Security-sensitive ChromeOS packages
Objective
This is a list of security-sensitive Portage packages that the ChromeOS team should strive to update quickly in the event of a security bug in them.
On an incoming security bug report, the ChromeOS security sheriff should ideally update the package themselves, or find an owner that can commit to updating the package quickly, namely before the end of their sheriff shift. Bear in mind that sometimes there will be no upstream fix for the bug, in which case the package should be updated as soon as a fix is available.
Rules
- The package has to be a third-party package (i.e. nothing from
chromeos-base). - The kernel doesn't count.
Packages
dev
dev-db/sqlitedev-libs/expatdev-libs/glibdev-libs/jsoncppdev-libs/libpcredev-libs/libpcre2dev-libs/libxml2dev-libs/openssldev-libs/protobuf
media
media-libs/freetypemedia-libs/libpngmedia-libs/tiff
net
net-dns/avahinet-fs/sambanet-libs/libmicrohttpdnet-libs/libpcapnet-misc/curlnet-misc/dhcpcdnet-misc/modemmanager-nextnet-misc/opensshnet-misc/tlsdatenet-print/cupsnet-print/hplipnet-vpn/openvpnnet-vpn/strongswannet-wireless/bluez(hopefully this is going away soon)net-wireless/wpa_supplicant
sys
app-arch/unrarsys-apps/dbussys-apps/restoreconsys-apps/usbguardsys-fs/fusesys-fs/fuse-archivesys-fs/mount-zipsys-fs/rar2fssys-fs/udevsys-libs/glibcsys-libs/libselinux-2.7sys-libs/zlib