3 ms·
I'm genuinely happy for you that your work doesn't labor under the constraints that many, many (many) environments in the real world require. But that doesn't
by jccc 8y ago
I'm genuinely happy for you that your work doesn't labor under the constraints that many, many (many) environments in the real world require.
But that doesn't mean those places/organizations/projects don't exist, even if you're unaware of them or don't think they're worthy of WordPress developers' efforts.
- debacle 8y agoUsing any version of PHP before PHP 5.6 is reckless from a security standpoint, let alone a language feature and performance standpoint. If you are on a version of PHP that old, you should make upgrading a very high priority. Edit - downmodders, please see: http://php.net/supported-versions.php http://php.net/supported-versions.php
- jccc 8y agoYou should inform the maintainers of CentOS, to take one example. CentOS 6.9 (supported until November 2020) runs 5.3 with backported security and maintenance updates. Newer versions are not available from them for 6.9. The issue is not that upgrading cannot or should not be done outside of their repos, but that many, many developers and site admins for various strong reasons are not in a position to do so. There may be other dependencies on either CentOS 6.9 or earlier-than-latest PHPs, or they may not have the freedom to switch distros or PHPs for any number of reasons. Please consider the possibility that you do not understand the real world in which many, many developers work.
- debacle 8y agoYou're using a version of the php software that is not receiving security updates. While CentOS might be supporting 6.9 until 2020, that doesn't mean Redhat is going to be performing security updates on PHP. Ubuntu obviously is updated a bit faster than CentOS, however you still need to use PPAs to receive the latest versions of PHP. > many, many developers and site admins for various strong reasons are not in a position to do so. I'm not convinced that this is a valid argument. If these versions of PHP were still supported, sure, but they are not and that is the real risk. > Please consider the possibility that you do not understand the real world in which many, many developers work. This is stand-offish and rude.
- gtCameron 8y ago> That doesn't mean Redhat is going to be performing security updates on PHP. That is actually exactly what it means. RedHat backports security fixes to 5.3 in order to support it, even though 5.3 is not fixed upstream in PHP https://access.redhat.com/security/updates/backporting https://access.redhat.com/security/updates/backporting
- snowwrestler 8y agoTo be more specific, Red Hat is is backporting these security fixes into Red Hat Enterprise Linux (RHEL), and that's why (one reason why) RHEL costs money. People pay for RHEL when they want someone else to manage a distro for security and stability; this is one example of how Red Hat does that. CentOS then gains the benefit of this work when Red Hat passes their changes downstream to CentOS.
- johannes1234321 8y agoThe point is that many WordPress users don't know what PHP is, they got some cheap web space, put WordPress up and run it for their website/blog. The hosted doesn't really care either, they want to be cheap. Sure, old PHP is out of support upstream, but RHEL and others still backport patches and there are only very few remotely exploitable bugs in the recent past of PHP, thus risk of a breach due to PHP (contrary to a non-updated WordPress/Drupal/...) is relatively small.
- fpoling 8y agoThe old PHP costs money. I know a company that realized that they could cut their operational costs significantly by upgrading PHP code from 2005 or so just because newer PHP is faster and they can get better utilization via microservices.
- johannes1234321 8y agoThat is true if you control the software running in top of it. For a cheap hoster upgrading PHP means they can put more customers on a single server, but causes support cost by customers who's apps don't work anymore and where no developer is there to fix it.