Skip to main content


Security Patches Are A Nightmare In Open Source Projects #Linux #YouTube https://youtu.be/dOUAPmcqq1U
in reply to Brodie Robertson

Maybe that’s why some people still believe proprietary software is more secure...
in reply to Brodie Robertson

Think the biggest issue is not the development of the patch but the role out. Unfortunately many admins that run on open source are a single admin single server and lag on updating their own machine.

They will also after time not pay attention to patch notifications and this leaves many unpatch vulnerable servers out on the internet.

Example would be someone hears about nextcloud and thinks it be cool to run their own. After a few months they quit paying attention to the server even if they use it daily.
in reply to Brodie Robertson

I'm with the curl team and similar approaches (some/most Apache projects). Get the fix with a generic description in main branches with CI going.

My employer was faced with a medium curl issue that most scanning software thought was critical, and explaining to customers that the LTS distro we used hadn't picked up the fix yet. Maddening situations.

Lo, thar be cookies on this site to keep track of your login. By clicking 'okay', you are CONSENTING to this.