3 ms·
> I think the fix is fairly trivial Not at all. Package maintainers and the Security Team in Debian do plenty of manual work to backport and test security fixe
by debiandev 8y ago
> I think the fix is fairly trivial
Not at all. Package maintainers and the Security Team in Debian do plenty of manual work to backport and test security fixes.
> As soon as a security issue pops up for one of their dependencies, their automation automatically compiles a new version
That pulls down new releases for the dependency instead of backporting a security fix.
Now you have no guarantee that the new binary will behave like the old one (minus the vuln).
On the contrary, it would be practically a new release.
A lot of companies have security policies allowing security updates on live production systems.
A complete rebuild against new libraries is not that.