5 ms·
> The problems of shared library version inconsistency have gone. No noticeable downsides. Sure, as long as you commit to releasing an updated version if a vul
by ris 5y ago
> The problems of shared library version inconsistency have gone. No noticeable downsides.
Sure, as long as you commit to releasing an updated version if a vulnerability is ever found in your version of rustls.
Edit: oh, and in such a case you should probably release your own CVE too, else not everyone will get the nudge to update.
- DasIch 5y agoOpenSSL is not great about compatibility. If you link to it dynamically, there is a good chance users have to recompile when it is updated which in practice means they'll need to update. This theoretical advantage of shared libraries also doesn't materialize, if containers are used.
- ris 5y agoI do sympathize as I spend a lot of my time maintaining distro packages. But I also fear that in this new world of golang and rust projects with statically linked libraries, few people take their reporting responsibilities seriously. Hell, if they did, a serious vulnerability in a commonly used library would result in an avalanche of CVEs.
- cjg 5y agoWell our product was already something that included the openssl library, so we would have had to release a new version of our product when there's a patched version of openssl anyway. At least updating it is easy now - we've put a lot of effort into that process recently.