4 ms·
Why would you patch a security vuln in a later version? Should be patched in all versions.. that's what semver is for.
by bfivyvysj 5mo ago
Why would you patch a security vuln in a later version? Should be patched in all versions.. that's what semver is for.
- jpleger 5mo agoAh yes the incredibly common practice of... checks notes backporting security packages in node packages.
- kijin 5mo agoSemver doesn't help if you just declare all older versions EOL. What you're looking for are Debian stable packages. :p
- raincole 5mo agoWho is 'you' here? All of the npm package maintainers? Yes, if they all just backport security patches we'll be fine. No, people are not going to just.
- pavon 5mo agoA patch updates is a newer version, and they are just as likely to be compromised by supply chain attacks as minor or major updates.
- dsl 5mo agoNot exactly. Security patches aren't like bugs or features where you can just roll a new version. Often patches need to be backported to older versions allowing software and libraries to be "upgraded" in place with no other change introduced. Say you had software that controlled the careful mix of chemicals introduced into a municipal water supply. You just don't move from version 1.4 to 3.2, you fix 1.4 in place.
- thfuran 5mo agoNo, you create version 1.4.19, which fixes a bug in 1.4.18.