ember-website icon indicating copy to clipboard operation
ember-website copied to clipboard

Clarification on security page's update policy:

Open NullVoxPopuli opened this issue 4 years ago • 8 comments

Page: https://emberjs.com/security

Towards the bottom, the page mentions that security patches are applied to All releases under maintenance, but it's not clear what all are the "releases under maintenance".

It'd be awesome if that could be clarified somewhere -- and what it means for folks who maybe would want to be a little conservative about their updates, maybe using Stable - 1 releases (being one release behind to get as many bug fixes as possible)?

NullVoxPopuli avatar Mar 23 '21 16:03 NullVoxPopuli

My two cents on interpreting All releases under maintenance is all the current LTS releases (~ 54 weeks) and all the intervening releases between stable and the most recent LTS? Looking at the last security bug CVE-2015-7565. Looks like security was patched on multiple versions from LTS to stable?

fozy81 avatar Mar 24 '21 18:03 fozy81

This issue has been automatically marked stale. If this issue is something that still needs work, please add a comment and it will remain open, otherwise it will close in 7 days. You are welcome to open a new issue if you miss the window. Thanks!

stale[bot] avatar Jul 30 '21 03:07 stale[bot]

Yes, still needs work

NullVoxPopuli avatar Jul 30 '21 03:07 NullVoxPopuli

This issue has been automatically marked stale. If this issue is something that still needs work, please add a comment and it will remain open, otherwise it will close in 7 days. You are welcome to open a new issue if you miss the window. Thanks!

stale[bot] avatar Jan 09 '22 01:01 stale[bot]

Bad bot

NullVoxPopuli avatar Jan 09 '22 01:01 NullVoxPopuli

@mixonic what do you think?

MelSumner avatar Mar 05 '22 00:03 MelSumner

This issue has been automatically marked stale. If this issue is something that still needs work, please add a comment and it will remain open, otherwise it will close in 7 days. You are welcome to open a new issue if you miss the window. Thanks!

stale[bot] avatar Aug 13 '22 22:08 stale[bot]

Bad bot

NullVoxPopuli avatar Aug 13 '22 23:08 NullVoxPopuli

Update: the clarification is:

See the supported LTS releases: https://emberjs.com/releases/lts/ And (hopefully obviously) the current release.

@NullVoxPopuli would you do a PR that links to this or clarifies it? Thank you!

MelSumner avatar Mar 10 '23 19:03 MelSumner

ye! https://github.com/ember-learn/ember-website/pull/1001

NullVoxPopuli avatar Mar 10 '23 19:03 NullVoxPopuli

With the merging go #1001 we can close this issue :)

MinThaMie avatar Mar 22 '23 09:03 MinThaMie