3 ms·
> The researchers found that the median security release comes within four days of the corresponding fix. But in some cases, security releases are delayed up to
by mrpotato 5y ago
> The researchers found that the median security release comes within four days of the corresponding fix. But in some cases, security releases are delayed up to 20 days.
I am not really surprised. The people making the security fixes are likely not the ones who find and report the issue and the devs are then stuck playing catch up. (Assuming there's not "ethical disclosure").
> To improve the security of open source software, the researchers recommend that package maintainers keep security fixes private until their release.
Keeping the fixes private is a good idea but is only effective if the vuln. isn't already make public by a third party (like the guy who found it).
But aside from that small nitpick, I agree with the study's recommendations as described in the article.