Re: [SMW-devel] Security backports

2013-05-16 Thread Ryan Lane
On Thu, May 16, 2013 at 3:43 PM, Jeroen De Dauw wrote: > Hey, > > Great. So all security fixes in master are always backported here? >> > > They should be yes. If this does not happen, feel free to shout at me. > > > I was basing this off of past experience, where wikis I managed were often >> bro

Re: [SMW-devel] Security backports

2013-05-16 Thread Jeroen De Dauw
Hey, Great. So all security fixes in master are always backported here? > They should be yes. If this does not happen, feel free to shout at me. I was basing this off of past experience, where wikis I managed were often > broken due to SMW running trunk. > If it does still break at some point,

Re: [SMW-devel] Security backports

2013-05-16 Thread Ryan Lane
On Thu, May 16, 2013 at 3:29 PM, Jeroen De Dauw wrote: > Hey, > > > So... is the 1.8.x branch currently secure, or insecure? > > Apart from master it is the most secure branch we have. > > Great. So all security fixes in master are always backported here? > > > Using master isn't really an optio

Re: [SMW-devel] Security backports

2013-05-16 Thread Jeroen De Dauw
Hey, > So... is the 1.8.x branch currently secure, or insecure? Apart from master it is the most secure branch we have. > Using master isn't really an option as breaking changes land very often in SMW. What kind of breaking changes are you talking about? From a user perspective there are very r

Re: [SMW-devel] Security backports

2013-05-16 Thread Ryan Lane
On Thu, May 16, 2013 at 3:06 PM, Jeroen De Dauw wrote: > Hey, > > Until very recently we did not have stable branches to which we backported > anything. This was mainly due to lack of dev manpower. With the last big > release (1.8) we decided to try and maintain a branch to backport things > to, w

Re: [SMW-devel] Security backports

2013-05-16 Thread Jeroen De Dauw
Hey, Until very recently we did not have stable branches to which we backported anything. This was mainly due to lack of dev manpower. With the last big release (1.8) we decided to try and maintain a branch to backport things to, which we named 1.8.x. The general notion here is to backport all non

[SMW-devel] Security backports

2013-05-16 Thread Ryan Lane
I recently noticed that a vulnerability we had fixed in SMW master hadn't been applied to any of the stable branches. We pushed it into the stable branches and merged it. This made us wonder how things were being handled, though. Are security fixes that go into master also applied in the stable br