Status and maintenance of v3.4.1-sec-patches3 & v3.2.7-sec-patches3 #1095
Replies: 2 comments 1 reply
My message above as someone also asked this via the Discord. But essentially;
Yes.
For quite some time, yes. Primarily for Ubuntu/Deb LTS.
Yes.
Not currently. Is that wanted?
.patch files then simply replay that onto your branch and archive it in the way required by your downstream. |
|
The v3.4.1-sec-patches4 and v3.2.7-sec-patches4 backport branches are now available. They contain the security and compatibility corrections applicable to those older release lines after After thinking it over, release tarballs are likely not best. Downstreams will maintain these older versions in different ways so the branches are intended as reviewable sources from which maintainers can cherry-pick commits or construct their own patch series. Users who can upgrade should prefer using the latest version of rsync |
Uh oh!
There was an error while loading. Please reload this page.
Hello Team,
Could you please clarify the status and maintenance model of the following branches?
v3.4.1-sec-patches3
v3.2.7-sec-patches3
We are looking at using these security patch branches for downstream maintenance of rsync versions 3.4.1 and 3.2.7.
In particular, could you please clarify:
Are these branches considered official rsync security-maintenance branches?
Are they expected to remain available?
If additional security fixes are required, is there an intention to create future branches such as v3.4.1-sec-patches4, v3.4.1-sec-patches5, or v3.2.7-sec-patches4, etc.?
Is there an official archive/tarball available for these security patch branches?
What is the recommended way for downstream projects to consume these security fixes?
We would like to understand the intended maintenance model for these branches before using them as a downstream security source.
Thanks!
All reactions