>> A few days ago, three CVEs for Nginx and were fixed in 1.8.1. Upstream >> only maintain 1.8.x and above, so they didn't release any fixes for >> older versions of Nginx. I was able to backport the relevant commits to >> Nginx 1.6.x on EL7. >> > > Thank-you for your request. I think that this is a good candidate for a > break in all three channels. I will try to get enough EPSco people to look > at this and give feedback while we are at FOSDEM. Hope to have a +1 for you > soon
So for at least EL7 there's going be some fairly regular and consistent rebasing of a number of components to newer versions so it might be that some long running LTS versions might not build or work with newer rebased libraries. I'm thinking of desktop and other related stuff here, and probably some stuff around crypto. In short we might want to put together a policy for at least EL7 for rebases that covers the rebase of components for support of newer underlying components. Peter _______________________________________________ epel-devel mailing list epel-devel@lists.fedoraproject.org http://lists.fedoraproject.org/admin/lists/epel-devel@lists.fedoraproject.org