[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: ownCloud security support



On Wed, May 04, 2016 at 08:35:03PM +0100, Dominic Hargreaves wrote:
> Hi all,
> 
> Firstly, thank you, David, for your excellent work packaging ownCloud
> and its dependencies. It allowed me a very easy setup for an installation
> which has been really valuable so far. (I will need to think carefully
> about future plans for this service.)
> 
> Given the recent removal of owncloud from Debian unstable[1] for
> understandable reasons, there is an obvious question about what
> support we can expect for owncloud in stable. According to the upstream
> website[2] 7.x is no longer security-supported.
> 
> Perhaps the security team could comment on this and consider whether
> end of support is appropriate?

We can probably backport security issues for a while. It's hard to predict 
of course, if they have some kind of "we totally messed up the design and 
need to rewrite parts of owncloud to fix that vulnerability" (not totally 
unlikely given the history of owncloud...) vulnerability we might reach a
point where we'll need to EOL it.

It's certainly not something I expect to make it into a jessie LTS, though.

Cheers,
        Moritz


Reply to: