Skip to content

Why so many active release tracks? Any reason(s) to not just use the latest? #3201

Answered by vlsi
CharlieReitzel asked this question in Q&A
Discussion options

You must be logged in to vote

Here are some challenges:
a) Imagine the system uses 42.2.0, and imagine the "current" version is 42.9.0. Imagine a CVE arrives that is applicable to all the versions. Even though individual changes like 42.2.0 -> 42.3.0, 42.3.0 -> 42.4.0 might be small, there might be many subtle incompatibilities along the way which might make the upgraded application fail or silently corrupt data. If we force everybody to fully retest their systems just in order to fix security, it would be too much hassle without extra gain.

Remember, the last CVE was CVSS 10 of 10. Sure people got notifications from their vulnerability scanners, and sure they needed an upgrade path. Asking everybody to upgrade to "th…

Replies: 5 comments 3 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@vlsi
Comment options

Answer selected by davecramer
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
2 replies
@vlsi
Comment options

@laurenz
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
5 participants