> On 18. Oct 2019, at 17:40, Jim Sinclair <[email protected]> wrote:
>
> Can you please update the Security advisory to include 2.190.1 if it applies?
Our security advisories don't list which releases have the fix, it only lists
the first release of each release line (in the case of core, weekly and LTS) to
have the fix. All subsequent releases are implied. So 2.190.1 isn't listed
because it is the successor of 2.176.4.
The reason it appears in the LTS changelog for 2.190.1 is that the section
"changes since 2.190" specifically lists, well, everything that is new in
2.190.1 compared 2.190. This section is basically irrelevant to admins who are
on the LTS line anyway, but it makes sense to document somewhere what changed
over 2.190. It's very unusual that we need to back port something to a ".1" LTS
release that was already in a previous LTS release, but is has happened before,
and would always be listed here.
Note how the August 28 advisory is also mentioned in the same changelog entry,
since those fixes were only in the 2.192 weekly and therefore had to be
backported. Yet, that advisory doesn't mention 2.190.1 either, and for the same
reason as in the September 25 advisory: In neither case was it the first LTS
release containing the fixes.
I added the note for 2.176.4, because it was not a regularly scheduled release.
According to https://jenkins.io/download/lts/ this release should not exist,
and the note explains why it does anyway.
--
You received this message because you are subscribed to the Google Groups
"Jenkins Developers" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To view this discussion on the web visit
https://groups.google.com/d/msgid/jenkinsci-dev/7B10CA47-A706-4613-8CF2-48CC87A722DF%40beckweb.net.