OpenWrt Security Advisories
openwrt.org
openwrt.org
I often delay updating my router because it takes ~20 minutes of work to reinstall packages, manually merge config files, and make SSH stop complaining about the host key.
There is an incentive to use as few features as possible, because every divergence from the base config is a perpetual maintenance burden.
Thanks for the heads up OP
https://openwrt.org/releases/22.03/notes-22.03.X
...where "X" is 0 to 5.The OpenWrt team is highly active and responsive, all vulnerabilites are patched. Someone has just forgotten to update the wiki.
I hope there is some rationale for why the security fixes in later releases were not serious enough to warrant an advisory on the security page, rather than it just being an oversight.
Then you should definitely take the task upon yourself in order to help everyone. A great chance to contribute. It's a wiki after all.
It seems to be a mostly volunteer driven project.
Proprietary SoC vendors use an fork of a very old version of the software so they're not invested.
Why not try engaging and see if you can help them automate advisories based on their issue tracker / got activity?
Because your attitude comes off as entitlement.
This isn't a project with massive corporate funding.
If the project isn't updating this page but they're actively making patch releases, what's the benefit?
There's this attitude when it comes to FOSS software where free users seem more entitled than paying users.
Isn't it significantly more entitled to ask volunteers provide a service?