tech-pkg archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
RC exception for net/py-twisted
Hi!
It seems that for net/py-twisted, there is a security issue which was
fixed 2 weeks ago, but only in an RC. Some software such as
chat/matrix-synapse have hence updated their dependency to require the rc1.
I know we usually don't update software to RCs, but I'd like to propose
that we make an exception for net/py-twisted, as they document that they
do not do security releases:
> We don’t do maintenance / patch releases, including for security
issues, due to lack of resources.
So because of that, they have released an rc1 2 weeks ago. But there is
still no stable release with the fix. According to
https://github.com/twisted/twisted/issues/12271
this is because they don't have time to do enough testing so just want
to keep the rc1 for a while.
With that in mind, I think it's fair to say that it's an upstream which
is broken enough to allow RCs in pkgsrc. I'd rather have an rc1 than a
release with known security issues that are trivial to exploit. For the
stable branches, that of course is problematic, but I'd be nice to at
least have the rc1 in trunk to fix this.
Opinions?
--
Jonathan
Home |
Main Index |
Thread Index |
Old Index