Thursday at 08:59 PM1 day Unraid OS 7.2.8 is a maintenance release that focuses on security, reliability, and keeping the platform current across storage, virtualization, networking, and web management.See the docs for more information : https://docs.unraid.net/unraid-os/release-notes/7.2.8/
22 hours ago22 hr 6 hours ago, warpspeed said:Shouldn't 7.3.3 also be available at the same time?Not necessarily. It is likely that 7.3.3 will include the same fixes that are in 7.2.8, but also any fixes specific to 7.3.x series so may take longer to get ready.
20 hours ago20 hr From a security patch posture point of view, it's not a good look to remediate an older release and not the current release at the same time.Basically like announcing that 7.3.2 now has exploitable vulnerabilities that are not patched.This is why others generally release patches for all supported OS versions at once.Releases that include security fixes should ideally be done at the same time.
20 hours ago20 hr Not sure I agree. You are in effect saying that Unraid should NOT make a 7.2.x release they have finished testing on that includes security fixes if they are still testing a 7.3.x release that includes those same fixes but also has other fixes so testing is still on-going.
7 hours ago7 hr I tend to agree @itimpi , especially since the vulnerabilities are in base operating system components and have been reported via CVE already. In a situation where others have let the cat out the bag you want to release as soon as possible (after your relevant quality assurance process)
2 hours ago2 hr 17 hours ago, itimpi said:Not sure I agree. You are in effect saying that Unraid should NOT make a 7.2.x release they have finished testing on that includes security fixes if they are still testing a 7.3.x release that includes those same fixes but also has other fixes so testing is still on-going.It's a release candidate, so clearly testing is not entirely complete or it'd be a final.and if for some reason they cannot release 7.3.x release candidate at the same time, then they shouldn't disclose details about security vulnerabilities until such time that all releases are available - though that is hard when it's upstream packages, or if already disclosed - which is even more reason to get all the releases out.Reality is they should have held this RC until the 7.3.x RC was also ready... or if they were working on some other features that aren't ready yet, but needed to get this RC out, then they should have also rolled an interim RC for 7.3.x including the same security patches as 7.2.x. Edited 2 hours ago2 hr by warpspeed
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.