Support changelogs in update-manager

Bug #1294604 reported by ITPROJECTS
34
This bug affects 8 people
Affects Status Importance Assigned to Milestone
elementary OS
Confirmed
Wishlist
Unassigned

Bug Description

It would be great for Elementary to provide changelogs. At the moment when one clicks on an update, there is no information as to what's new. A message come in the changes section "This update does not come from a source that supports changelogs."

This means that it isn't so easy to evaluate fixes directly from the updater, but only from browser for the individual bugs every time. This may cause some unintended security holes to develop, for example if the new bugfix upgrades one part, but deprecates another, without the user even being told of that, since changelogs aren't supported.

ITPROJECTS (itprojects)
information type: Private Security → Public Security
Revision history for this message
Sergey "Shnatsel" Davidoff (shnatsel) wrote :

I don't really understand the security part; the assumption here is that the user never has to install updates not marked as important security updates and never has to read changelogs to maintain a secure system. How can changelogs affect that and why should we force users to read them?

Changed in elementaryos:
importance: Undecided → Wishlist
status: New → Confirmed
summary: - Support CHANGELOGS
+ Support changelogs in update-manager
Revision history for this message
ITPROJECTS (itprojects) wrote :

For an ubuntu package there is usually a changelog saying something like:

"
-fixed bug #23498428 , changed security algorithm form "a=b+c" to "a = b*c"
"

Seeing this changelog, one may choose the older version that they are sure works for their specific machine.

The"update-manager" does not support elementary updates CHANGES descriptions. Meaning one cannot see what was changed untill they visit the specific bugpage in a browser. This in turn takes some time - visiting every bugpage finding what the newstuff is, checking it (line by line) and then installing it.

Wouldn't it be easier to just have some changelog support that would make all of this procedure quicker, nicer, safer, since it would reduce the time needed to evaluate an update-change.

information type: Public Security → Public
Revision history for this message
Narcis Garcia (narcisgarcia) wrote :

Reproduced with Ubuntu 16.04 (xenial) using Libre repository by git.actiu.net
(All packages there include debian/changelog file)

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.