Conill: The long-term consequences of maintainers’ actions
Conill: The long-term consequences of maintainers’ actions
Posted Sep 19, 2021 0:26 UTC (Sun) by robert_s (subscriber, #42402)In reply to: Conill: The long-term consequences of maintainers’ actions by wahern
Parent article: Conill: The long-term consequences of maintainers’ actions
But I think we're in for a shock the first time there's a really serious vulnerability in a widely used e.g. golang library. At that point, what do projects using that library do? Quietly bump their version, *maybe* make a note in the changelog, and move on? Or do like they should and release their own CVE? If they *don't*, what is the mechanism through which their users are supposed to get the nudge to upgrade? If they *do*, I'm certain the CVE process wouldn't be able to handle the avalanche effect from a widely used package. Do the users of the "recommended" distribution means (the official docker image, "just grab the binary"...) get the nudge somehow?
Or is the answer the increasingly familiar hand-wave of "just always run the latest version"? Because that might *sound* like an answer but it doesn't connect with the reality of running a system comprised of N thousand separate packages.
