tech-pkg archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

RC exception for net/py-twisted



Hi!

It seems that for net/py-twisted, there is a security issue which was fixed 2 weeks ago, but only in an RC. Some software such as chat/matrix-synapse have hence updated their dependency to require the rc1.

I know we usually don't update software to RCs, but I'd like to propose that we make an exception for net/py-twisted, as they document that they do not do security releases:

> We don’t do maintenance / patch releases, including for security issues, due to lack of resources.

So because of that, they have released an rc1 2 weeks ago. But there is still no stable release with the fix. According to

https://github.com/twisted/twisted/issues/12271

this is because they don't have time to do enough testing so just want to keep the rc1 for a while.

With that in mind, I think it's fair to say that it's an upstream which is broken enough to allow RCs in pkgsrc. I'd rather have an rc1 than a release with known security issues that are trivial to exploit. For the stable branches, that of course is problematic, but I'd be nice to at least have the rc1 in trunk to fix this.

Opinions?

--
Jonathan


Home | Main Index | Thread Index | Old Index