La "réponse" de Fedora au problème qu'a eu Debian (Fedora n'a jamais nié qu'un problème de ce type puisse lui arriver) : http://fedoraproject.org/wiki/PackagingDrafts/PatchUpstreamS(...)
All patches in Fedora spec files SHOULD have a comment above them about their upstream status. Any time you create a patch, it is best practice to file it in an upstream bug tracker, and include a link to that in the comment above the patch. For example:
[^] # Re: Mesures qui seront prises ?
Posté par IsNotGood . En réponse à la dépêche Découverte d'une faille de sécurité critique dans OpenSSL de Debian. Évalué à 1.
http://fedoraproject.org/wiki/PackagingDrafts/PatchUpstreamS(...)
All patches in Fedora spec files SHOULD have a comment above them about their upstream status. Any time you create a patch, it is best practice to file it in an upstream bug tracker, and include a link to that in the comment above the patch. For example:
# http://bugzilla.gnome.org/show_bug.cgi?id=12345Patch0: gnome-panel-fix-frobnicator.patch
Ça vient d'être approuvé par le FESCo.
Notons que Fedora a toujours insisté pour bosser en upstream :
http://fedoraproject.org/wiki/PackageMaintainers/WhyUpstream
Il y a une réflexion pour mettre certains paquets critiques dans une catégorie spéciale.
Pour Debian ?
Ben j'imagine que ça doit encore parlementer.