-
-
Notifications
You must be signed in to change notification settings - Fork 632
Open
Description
I believe we should not perform other releases after a security releases has been announced.
- It's confusing for users if a release comes out before the expected security release date.
- It's a vulnerable release, it makes it unusable for users knowing it has vulnerabilities.
- It disrupts the tooling. In the security release process, the tool requires to know in which patch a vulnerability will be fixed, and which is vulnerable. If a new release comes after we declared it in the
vulnerabilities.json, it becomes inaccurate. It requires coordination.
I propose we delay regular releases to after the security release.
BethGriggs, RafaelGSS and fengmk2
Metadata
Metadata
Assignees
Labels
No labels