On Wed, 18 Jan 2023 at 03:08, Randy MacLeod <[email protected]> wrote: > So far, there haven't been many Rust/Cargo CVEs so maybe we're making > too big a deal out of this. I certainly don't miss the deluge of memory > management CVEs that > C/C++ applications suffer from!
For what it's worth I'm with you here, and I actually have an even more radical view (that may offend some - apologies). I think this whole 'CVE backporting' business is both enormously wasteful and never complete (or even close to it). Backporting CVEs and the stable release policy is basically a cover-up for bad (or altogether absent) CI at the project users side. If you upgrade a component, and it causes trouble, the trouble should be caught by pipeline, and not in the end product when the update has shipped. The saner policy would have been 'a Yocto stable release contains component versions all within their support windows by respective upstreams'. If the only supported version is the latest one, then so be it. Alex
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#176075): https://lists.openembedded.org/g/openembedded-core/message/176075 Mute This Topic: https://lists.openembedded.org/mt/96218038/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
