Brief items
Security
Security quote of the week
That implies that the solution to look for isn't a winning persuasive argument, but instead is a way to get the developer more resources, either by somehow getting them more time to work on their project or by making the cost of better engineering process substantially smaller than it is now. GitHub's automated pull requests for dependencies with security vulnerabilities is a good example of the latter.
Kernel development
Kernel release status
The 5.7 merge window is open; it can be expected to close on April 12. See this article for a summary of what was merged in the early days of the 5.7 development cycle.Stable updates: 5.6.2 was released on April 2 with an important wireless networking regression fix; it was followed almost immediately by 5.5.15, 5.4.30, 4.19.114, 4.14.175, 4.9.218, and 4.4.218. Then, 5.6.3, 5.5.16, and 5.4.31 showed up on April 8.
Distributions
LineageOS 17.1 released
LineageOS 17.1 is out. This release of the Android-based distribution once known as CyanogenMod includes a rebase onto the Android 10 release of the Android Open Source Project, improved theme support, support for on-screen fingerprint sensors, the ability to use biometric sensors to control access to apps, and more. "On the whole, we feel that the 17.1 branch has reached feature and stability parity with 16.0 and is ready for initial release. With 17.1 being the most recent and most actively developed branch, on April 1st, 2020 it will begin receiving nightly builds and 16.0 will be moved to weekly builds."
Distribution quote of the week
I agree that this has fallen out of fashion to an extent, and the "let's just outsource everything that isn't actively building bits into OS images" mindset is in tune with Current Industry Thinking and there is a sustainable logic behind it. Personally I still think it comes with significant issues, though, because there were a lot of what management is pleased to call "intangibles" that went along with doing all that work. We had an awful lot of "in-house" knowledge about a whole range of stuff because we *did* build and maintain and deploy and support all of these bits.
Development
Firefox 74.0.1
Firefox 74.0.1 has been released with two security fixes. CVE-2020-6819 is a use-after-free when running the nsDocShell destructor and CVE-2020-6820 is a use-after-free when handling a ReadableStream. In both cases there have been targeted attacks in the wild abusing these flaws. These issues have also been fixed in Firefox ESR 68.6.1.Firefox 75.0
Firefox 75.0 has been released. New features include improvements to the address bar, making search easier, all trusted Web PKI Certificate Authority certificates known to Mozilla will be cached locally, and Firefox is available as a Flatpak. See the release notes for more details.
Page editor: Jake Edge
Next page:
Announcements>>
