Email alerts for major security issues

Where would I sign up for that? Not a mailing list for a discussion and not everything related to the topic and countless issues, data breaches and such. Just alerts going out promptly for major issues that could require immediate personal action.

I’m posting here because this is prompted by the xz issue (I’m on 39 so it was fine). I would like to hear about such issues related to or affecting Fedora. If it’s an appropriate source, I wouldn’t mind other software/topics that I could choose such as Thunderbird. But I don’t want everything out there, and not at the expense of speed.

As far as I know, there is no such thing. What you can do is to run dnf updateinfo list updates security, but it’s manual. Something automatic will require a connected server and/or a crontab that run that and send an email.

Nothing is impossible. What I do is that I register my systems into my server’s cockpit and check updates there, but it was really a home lab, that I won’t recommend to reproduce in production. You can also use:

  • The Foreman with katello (the base for Red Hat Satellite)
  • Red Hat Satellite
  • AWX

But for all of them to send you automatic emails you would require to configure a lot of things.

Good luck and happy hacking

2 Likes

As you note, those “countless issues” are constant and hard to keep up with. On the other hand, because the really big things are (thankfully) infrequent, we don’t have a specific channel set up to address them. In the past, we have sent messages to the Fedora Announce list in critical situations — see for example Fedora Infrastructure information on Openssl vulnerability (CVE-2014-0160/heartbleed) - announce - Fedora Mailing-Lists.

We didn’t do that this time, as the xz malware did not affect the general release. However, we did publish information in Fedora Magazine: CVE-2024-3094: Urgent alert for Fedora Linux 40 and Rawhide users - Fedora Magazine and CVE-2024-3094: All Clear - Fedora Magazine.

It might not be a terrible idea to add a #critical-security-alert tag for News & Announcements, which we could use in these situations.

Thanks for sharing you thoughts. I’ll have to just check a few locations periodically.