• 1 Post
  • 92 Comments
Joined 3 years ago
cake
Cake day: July 2nd, 2023

help-circle





  • dondelelcaro@lemmy.worldto196@lemmy.blahaj.zoneDebian rule
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    1
    ·
    10 days ago

    This is a challenge all distributions have which want to keep stability, which means shipping older versions (ideally with long term support) with only security updates for the lifetime of the distribution. It’s totally ok for upstream developers to not support any of those old versions too; they’re not being paid either.


  • dondelelcaro@lemmy.worldto196@lemmy.blahaj.zoneDebian rule
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    1
    ·
    10 days ago

    The openssl change was communicated with upstream at the time, but no one from upstream pointed out the issue (not surprisingly, because the change seemed like an innocuous fix to an unassigned variable.)

    We (Debian) fix bugs and send upstream the changes all the time, so this kind of thing happens. (Upstreams introduce these kind of bugs too; it’s the nature of software development.)