|
|
Log in / Subscribe / Register

Fast upgrades

Fast upgrades

Posted Apr 22, 2026 15:53 UTC (Wed) by mathstuf (subscriber, #69389)
In reply to: Fast upgrades by ju3Ceemi
Parent article: Dependency-cooldown discussions warm up

If you attach a CVE report (or equivalent) to an upload, this makes sense to me. This (probably?) involves a lot more work than just stealing a secret key. Additionally, if something *explicitly* requests the version, it should be made available (so that I can update dependent packages immediately without having to wait N days per dependency depth to update an entire stack).


to post comments

Fast upgrades

Posted Apr 22, 2026 15:56 UTC (Wed) by ju3Ceemi (subscriber, #102464) [Link] (1 responses)

Everybody can issue CVEs

Fast upgrades

Posted Apr 22, 2026 19:03 UTC (Wed) by mathstuf (subscriber, #69389) [Link]

Sure, but a CVE is a big flare one might not want to attach to their trojaned upload.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds