Document security fixes in FAQ
* doc/misc/efaq.texi (New in Emacs 29): Recommend using Emacs 29.4. * doc/misc/efaq.texi (Security risks with Emacs): New item with a recommendation to upgrade Emacs for improved security.
This commit is contained in:
parent
d063af203c
commit
d95f039af4
1 changed files with 18 additions and 0 deletions
|
@ -1014,6 +1014,9 @@ Here's a list of the most important changes in Emacs 29 as compared to
|
||||||
Emacs 28 (the full list is too long, and can be read in the Emacs
|
Emacs 28 (the full list is too long, and can be read in the Emacs
|
||||||
@file{NEWS} file by typing @kbd{C-h n} inside Emacs).
|
@file{NEWS} file by typing @kbd{C-h n} inside Emacs).
|
||||||
|
|
||||||
|
Note that Emacs 29.3 and 29.4 both contained important security fixes.
|
||||||
|
Upgrading is particularly important if you use Emacs as a mail client.
|
||||||
|
|
||||||
@itemize
|
@itemize
|
||||||
@item
|
@item
|
||||||
Emacs can now be built with the
|
Emacs can now be built with the
|
||||||
|
@ -3661,6 +3664,21 @@ same privileges as the Emacs process itself. Be aware of this when
|
||||||
you use the package system (e.g. @code{M-x list-packages}) with third
|
you use the package system (e.g. @code{M-x list-packages}) with third
|
||||||
party archives. Use only third parties that you can trust!
|
party archives. Use only third parties that you can trust!
|
||||||
|
|
||||||
|
@item
|
||||||
|
Using an out-of-date Emacs version.
|
||||||
|
|
||||||
|
For security purposes, we recommend always using the latest officially
|
||||||
|
released version of Emacs. Using old versions of Emacs might put your
|
||||||
|
security at risk, as newer versions occasionally include important
|
||||||
|
security fixes. Please review the Emacs release notes and the
|
||||||
|
@file{etc/NEWS} file for details.
|
||||||
|
|
||||||
|
Upgrading to the most recent version is particularly important if you
|
||||||
|
use Emacs as a mail client, or to edit files that come from untrusted
|
||||||
|
sources. You should be able to install the latest version of Emacs
|
||||||
|
through your system's package manager, and it is always available at
|
||||||
|
@uref{https://www.gnu.org/software/emacs/, the Emacs website}.
|
||||||
|
|
||||||
@item
|
@item
|
||||||
The @code{file-local-variable} feature. (Yes, a risk, but easy to
|
The @code{file-local-variable} feature. (Yes, a risk, but easy to
|
||||||
change.)
|
change.)
|
||||||
|
|
Loading…
Add table
Reference in a new issue