> In particular, it assumes that critical bugs are identified early in the
> process and released. Sounds like that is badly broken here.
That sounds ideal, but what sort of release process could reliably accomplish that goal with respect to security bugs? Tell people to have their security-related discussions during the first half of a new release, analogous to the kernel merge window?
Posted Mar 6, 2012 16:57 UTC (Tue) by man_ls (subscriber, #15091)
[Link]
I am assuming give a high priority to fixing critical issues before adding new features. Apparently this particular problem has been known for a long time but has gone unfixed.