On Fri, 2011-12-09 at 13:55 +0100, Andreas Färber wrote:
> Am 05.12.2011 21:08, schrieb Justin M. Forbes:
> > Typically I get a flurry of patches shortly after
> > a release (and they have already started for 1.0).  I have tried to get
> > a .1 release out in a timely manner, and then it seems patches for
> > stable become few and far between.  In the 0.14 and 0.15 series, not
> > even enough to warrant a .2 release.  Perhaps this is due to lack fixed
> > issues, or lack of effort to submit to stable.
> 
> > 3) Security fixes do not follow this schedule, and will trigger a stable
> > release as needed.
> 
> I would've thought that the usb-ccid CVE alone warrants a 0.15.2 of qemu
> and qemu-kvm. I am surprised nothing has happened there yet...
> 
> http://patchwork.ozlabs.org/patch/128064/
> 

I suppose that also brings up the question of how long a stable branch
should be supported?  Perhaps we should do stable through 2 release
cycles, so that 0.15 stable would stop when 1.1 is released?

Justin


Reply via email to