3 ms·
Damn; I assumed since it was shipped in Debian Stable it had all the same guarantees as the rest of the distro, but I guess the browser codebases tend to be suc
by technomancy 10y ago
Damn; I assumed since it was shipped in Debian Stable it had all the same guarantees as the rest of the distro, but I guess the browser codebases tend to be such security disasters that they can't necessarily keep up.
- mgbmtl 10y agoProjects release new versions of software not just for new features, but (one would hope) constant improvements to the underlying architecture. Firefox in particular has been evolving quickly, with many of under-the-hood improvements that may not fix "high-risk" security issues, but constantly improve security directly or indirectly (e10s?). You can't expect maintainers of an ESR to backport all those things. There's always a risk in adopting the latest version of a program, but there's also a risk with keeping the old, less actively maintained version. I get burned all the time with Debian Stable, running into bugs fixed in the latest version but not backported. (nonetheless, I do prefer Debian Stable to most other solutions) A project I'm involved in even has an automatic "toxic code" warning for PRs on known functions/classes that need to be refactored, and where monkey-patching will likely cause other security issues one way or another.