Marcus Meissner wrote:

>> Will a Novell programmer make the necessary patches to 1.4?
>> will SUSE (YOU) provide upgrade to 1.5 or 1.6... giving I'm
>> stuck with the 1.6 upgrade :-)
> 
> We currently do this, yes:
> $ ls -l /work/SRC/old-versions/10.0/all/mediawiki

> -rw-r--r--  1 root root    1604 2005-12-07 14:47 mediawiki-1.4.7-php4.4.1.diff

official last 1.4  version is 1.4.14

> 
>> php scripts are very sensitive materials. vulnerability
>> found there can severely impact a server.
> 
> Just do not use them. ;)

the server is just made to run these :-)

> 2 years of security updates, as with the dozen SUSE Linux releases
> before.

I don't question the security release, just the way they are
done.

at first glance it seems very expensive to fix programms
that where not entended to be when the developper do this
better (I beg) and free, just to stay with obsolete versions.

I mean if the developper of the app XXxx gives two years
security update, it seems enough to use them. if not, how
can you be sure? does this mean you have a programmer for
any and each package available on SUSE Linux? if yes is this
one included in the main developper team or working alone?

I think it's very interesting to know, I think you make
often internally more work than most people know and you are
not granted for it :-)

jdd

-- 
http://www.dodin.net
http://dodin.org/galerie_photo_web/expo/index.html
http://lucien.dodin.net
http://fr.susewiki.org/index.php?title=Gérer_ses_photos

---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to