[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Please allow drupal 4.5.3-1



On Fri, Jun 03, 2005 at 08:19:22AM +0200, Martin Schulze wrote:
> Steve Langasek wrote:
> > On Wed, Jun 01, 2005 at 07:16:00PM -0700, Ian Eure wrote:
> > > On Wednesday 01 June 2005 04:54 pm, Hilko Bengen wrote:
> > > > Just a few hours ago, the Drupal project has released version 4.5.3, a
> > > > bugfix release which fixes a serious security bug. I have created and
> > > > just uploaded a 4.5.3-1 package to unstable. Updated Debconf
> > > > translations are the only additional changes over 4.5.2-3 which is
> > > > the version in sarge.
> > > Any reason why you can't just apply the patch to fix that specific bug?

> > > And you probably want to be emailing the release team...

> > He did contact the release team; unfortunately, the diff between 4.5.2 and
> > 4.5.3 is rather large and I don't believe it's all security-related, so I
> > think this will have to be left for the security team after all.

> Umh, the release team most probably has even stricter rules than the
           ^^^^^^^ security, I guess :)
> release team when it comes to cluttering the diff...

Absolutely -- but the release team has a deadline before which the fix must
be in unstable in order for it to be included in sarge (and if everything
goes according to plan, this deadline is in 12 hours), whereas you can take
as much time as you want to going back and forth with the maintainer until
he gets it right. :)

-- 
Steve Langasek
postmodern programmer

Attachment: signature.asc
Description: Digital signature


Reply to: