3 ms·
> It's up to Fedora to support Go 1.16 on its own. It may be worthwhile for someone to maintain a list of Open Source projects with an EOL cycle that turned ou
by pledess 5y ago
> It's up to Fedora to support Go 1.16 on its own.
It may be worthwhile for someone to maintain a list of Open Source projects with an EOL cycle that turned out to be too fast for a popular Linux distribution, along with notes about where to find (potentially valid) security patches. For example, before long, https://groups.google.com/g/golang-announce https://groups.google.com/g/golang-announce will undoubtedly announce a security problem that's only fixed in 1.17.x and 1.18.x. If someone is already volunteering to maintain a tree of 1.16.15+backported-security-fixes, it might not be immediately obvious where to find that.
- cmeacham98 5y agoIsn't Fedora primarily developed by and used as an upstream by RedHat (i.e. IBM)? Why does anybody need to volunteer to maintain security patches for it, RH can't afford to assign a few engineers to secure the product their very existence is based off of?