امنیت
چگونگی گزارش مشکلات امنیتی
To report sensitive security issues in Guix itself or the packages it provides, you can write to the private mailing list guix-security@gnu.org. This list is monitored by a small team of Guix developers.
If you prefer to send your report using OpenPGP encrypted email, please send it to one of the following Guix developers using their respective OpenPGP key:
- Leo Famulari
- Tobias Geerinckx-Rice
- John Kehayias
امضاهای ارائه
ارائههای گیکس با یکی از کلیدهای OpenPGP زیر امضا شدهاند:
- 27D5 86A4 F890 0854 329F F09F 1260 E464 82E6 3562
- Maxim Cournoyer
- 3CE4 6455 8A84 FDC6 9DB4 0CFB 090B 1199 3D9A EBB5
- Ludovic Courtès
کاربران باید پیش از استخراج یا اجرای بارگیریهایشان، تأییدش کنند.
بهروز رسانیهای امنیتی
When security vulnerabilities are found in Guix or the packages provided by Guix, we will provide security updates quickly and with minimal disruption for users. When appropriate, a security advisory is published on the blog with the Security Advisory tag and on the info-guix
mailing list; guix pull --news
may also display the advisory.
Guix uses a “rolling release” model. All security bug-fixes are pushed directly to the master branch. There is no “stable” branch that only receives security fixes.