3 ms·
You should inform the maintainers of CentOS, to take one example. CentOS 6.9 (supported until November 2020) runs 5.3 with backported security and maintenance
by jccc 8y ago
You should inform the maintainers of CentOS, to take one example.
CentOS 6.9 (supported until November 2020) runs 5.3 with backported security and maintenance updates. Newer versions are not available from them for 6.9.
The issue is not that upgrading cannot or should not be done outside of their repos, but that many, many developers and site admins for various strong reasons are not in a position to do so. There may be other dependencies on either CentOS 6.9 or earlier-than-latest PHPs, or they may not have the freedom to switch distros or PHPs for any number of reasons.
Please consider the possibility that you do not understand the real world in which many, many developers work.
- debacle 8y agoYou're using a version of the php software that is not receiving security updates. While CentOS might be supporting 6.9 until 2020, that doesn't mean Redhat is going to be performing security updates on PHP. Ubuntu obviously is updated a bit faster than CentOS, however you still need to use PPAs to receive the latest versions of PHP. > many, many developers and site admins for various strong reasons are not in a position to do so. I'm not convinced that this is a valid argument. If these versions of PHP were still supported, sure, but they are not and that is the real risk. > Please consider the possibility that you do not understand the real world in which many, many developers work. This is stand-offish and rude.
- gtCameron 8y ago> That doesn't mean Redhat is going to be performing security updates on PHP. That is actually exactly what it means. RedHat backports security fixes to 5.3 in order to support it, even though 5.3 is not fixed upstream in PHP https://access.redhat.com/security/updates/backporting https://access.redhat.com/security/updates/backporting
- snowwrestler 8y agoTo be more specific, Red Hat is is backporting these security fixes into Red Hat Enterprise Linux (RHEL), and that's why (one reason why) RHEL costs money. People pay for RHEL when they want someone else to manage a distro for security and stability; this is one example of how Red Hat does that. CentOS then gains the benefit of this work when Red Hat passes their changes downstream to CentOS.