Re: Fwd: [MediaWiki-announce] MediaWiki security release: 1.20.3 and 1.19.4

2013-03-05 Thread janI
On 5 March 2013 08:46, Andrea Pescetti pesce...@apache.org wrote: Daniel Shahaf wrote: if somebody replies to your post and says Hey, false negative, you really want_that_ to happen privately. That was my concern too. Jan is perfectly right that he merely forwarded a public security

Re: Fwd: [MediaWiki-announce] MediaWiki security release: 1.20.3 and 1.19.4

2013-03-05 Thread Daniel Shahaf
janI wrote on Tue, Mar 05, 2013 at 09:08:33 +0100: On 5 March 2013 08:46, Andrea Pescetti pesce...@apache.org wrote: Daniel Shahaf wrote: if somebody replies to your post and says Hey, false negative, you really want_that_ to happen privately. That was my concern too. Jan is

Re: Fwd: [MediaWiki-announce] MediaWiki security release: 1.20.3 and 1.19.4

2013-03-05 Thread Andrea Pescetti
janI wrote: Instead of discussing what I should have done (and making me think why do I care, maybe we could concentrate on whether or not it should be applied, and if there are any volunteers to test it. OK, let's leave security out of this and consider it just an infrastructure update. Then

Fwd: [MediaWiki-announce] MediaWiki security release: 1.20.3 and 1.19.4

2013-03-04 Thread janI
Hi. As you can read below, mediawiki has just released a security release. We are currently not hit by the issues noted in the mail. However I would like to ask the community if we should upgrade or wait for a later release ? if we upgrade, we have to test all extensions again. rgds Jan I.

Re: Fwd: [MediaWiki-announce] MediaWiki security release: 1.20.3 and 1.19.4

2013-03-04 Thread Andrea Pescetti
janI wrote: As you can read below, mediawiki has just released a security release. We are currently not hit by the issues noted in the mail. However I would like to ask the community if we should upgrade or wait for a later release ? Security issues are one of the few cases where we prefer

Re: Fwd: [MediaWiki-announce] MediaWiki security release: 1.20.3 and 1.19.4

2013-03-04 Thread Daniel Shahaf
Andrea Pescetti wrote on Mon, Mar 04, 2013 at 22:05:42 +0100: janI wrote: As you can read below, mediawiki has just released a security release. We are currently not hit by the issues noted in the mail. However I would like to ask the community if we should upgrade or wait for a later release

Re: Fwd: [MediaWiki-announce] MediaWiki security release: 1.20.3 and 1.19.4

2013-03-04 Thread janI
On 5 March 2013 00:24, Daniel Shahaf danie...@apache.org wrote: Andrea Pescetti wrote on Mon, Mar 04, 2013 at 22:05:42 +0100: janI wrote: As you can read below, mediawiki has just released a security release. We are currently not hit by the issues noted in the mail. However I would like

Re: Fwd: [MediaWiki-announce] MediaWiki security release: 1.20.3 and 1.19.4

2013-03-04 Thread Daniel Shahaf
janI wrote on Tue, Mar 05, 2013 at 00:41:42 +0100: On 5 March 2013 00:24, Daniel Shahaf danie...@apache.org wrote: Andrea Pescetti wrote on Mon, Mar 04, 2013 at 22:05:42 +0100: janI wrote: As you can read below, mediawiki has just released a security release. We are currently not hit

Re: Fwd: [MediaWiki-announce] MediaWiki security release: 1.20.3 and 1.19.4

2013-03-04 Thread Andrea Pescetti
Daniel Shahaf wrote: if somebody replies to your post and says Hey, false negative, you really want_that_ to happen privately. That was my concern too. Jan is perfectly right that he merely forwarded a public security announcements, and that there is absolutely nothing wrong in this in