This grossly understates the problem.
The debian xscreensaver package was years old, and contained bugs related to screen locking which were an actual security issue.
Your comment is in very poor taste.
This grossly understates the problem.
The debian xscreensaver package was years old, and contained bugs related to screen locking which were an actual security issue.
Your comment is in very poor taste.
So they grossly understate the problem, make it seem like it’s the person authoring the software at fault or the one who’s being unreasonable.
They’re quick to tell you how great the maintainers are, how much effort they put in for free but they don’t share that same love for the author of the package. You know, the person who actually wrote the software. They don’t acknowledge that without the author they’d have no software to begin with, and that providing support to older versions of software is a cost to the author. Not just older, but possibly broken in subtle ways because of the patches applied on top. The author still gets all the blame and all the support requests for changes they didn’t make.
To be clear, there’s nothing wrong with wanting to run old, stable software. No one questions that their distro is “the most stable”. That they cannot or will not see the costs of doing so on the author is a shortcoming, but there’s no solving that.
> To be clear, there’s nothing wrong with wanting to run old, stable software.
I personally run on latest, apply all updates zealously within a week or two.
They have different goals/purposes, often, and they frequently don't line up with my own.
Maintainers are exhausting in their own right, they do a ton of work and so they think their decisions are more important because of the work they do, user be damned...
Authors usually only care about their version of the software.
I think, a better medium, would be if a third party is packaging an application, perhaps they should always explicitly state they are the ones packaging it. Then there is less confusion.
Or, you know, let the author keep control of that...
In contrast, Red Hat Enterprise Linux, a distro funded by IBM and countless faceless backers, has recently stopped patching many vulnerabilities, recommending to their users to rely on mitigations instead, despite the availability of upstream patches.
Furthermore, the recent vulnerability threatscape is inundated with CVE hunters who are desperate to call the most minor degradation of service a vulnerability. For a community project (and apparently an enterprise-serving megacorporation), this causes patching fatigue.
I'm not really sure why everyone is focusing on that phrase, though. I think it's pretty clear if you read any of the source material, as said, that that is not an accurate representation of what was going on, and I would have also expected "every 30 minutes" to be a pretty clearly hyperbolic expectation for anyone to process updates after.
Is everyone focusing on the phrase? I thought I asked about it, and that's all that's happened.
> I would have also expected "every 30 minutes" to be a pretty clearly hyperbolic expectation for anyone to process updates after
I couldn't imagine a benign use of hyperbole in timeliness when some expectations of timeliness are silly, and some are sensible. I thought I'd ask, in case there was a good faith reason for it, rather than just assume you're trying to use insinuation to change people's minds.