diff --git a/chapter03/packages.xml b/chapter03/packages.xml index 5b1976f47..aa927e60a 100644 --- a/chapter03/packages.xml +++ b/chapter03/packages.xml @@ -10,6 +10,21 @@ All Packages + + Read the security advisories + before downloading packages to figure out if a newer version of any + package should be used to avoid security vulnerabilities. + + The upstreams may remove old releases, especially when these + releases contain a security vulnerability. If one URL below is not + reachable, you should read the security advisories first to figure out + if a newer version (with the vulnerability fixed) should be used. If + not, try to download the removed package from a mirror. Although it's + possible to download an old release from a mirror even if this release + has been removed because of a vulnerability, it's not recommended to + use a release known to be vulnerable for building your system. + + Download or otherwise obtain the following packages: @@ -173,15 +188,6 @@ Home page: Download: MD5 sum: &expat-md5; - - The upstream may remove tarballs of the specific releases of - Expat when these releases contain a - security vulnerability. You should refer to - LFS security advisories - to figure out which version (with the vulnerability fixed) should - be used. You may download the vulnerable version from a mirror, - but it's not recommended. -