July 23Jul 23 Unraid OS 7.2.8 is a maintenance release that focuses on security, reliability, and keeping the platform current across storage, virtualization, networking, and web management.See the docs for more information : https://docs.unraid.net/unraid-os/release-notes/7.2.8/
July 24Jul 24 6 hours ago, warpspeed said:Shouldn't 7.3.3 also be available at the same time?Not necessarily. It is likely that 7.3.3 will include the same fixes that are in 7.2.8, but also any fixes specific to 7.3.x series so may take longer to get ready.
July 24Jul 24 From a security patch posture point of view, it's not a good look to remediate an older release and not the current release at the same time.Basically like announcing that 7.3.2 now has exploitable vulnerabilities that are not patched.This is why others generally release patches for all supported OS versions at once.Releases that include security fixes should ideally be done at the same time.
July 24Jul 24 Not sure I agree. You are in effect saying that Unraid should NOT make a 7.2.x release they have finished testing on that includes security fixes if they are still testing a 7.3.x release that includes those same fixes but also has other fixes so testing is still on-going.
July 24Jul 24 I tend to agree @itimpi , especially since the vulnerabilities are in base operating system components and have been reported via CVE already. In a situation where others have let the cat out the bag you want to release as soon as possible (after your relevant quality assurance process)
July 25Jul 25 17 hours ago, itimpi said:Not sure I agree. You are in effect saying that Unraid should NOT make a 7.2.x release they have finished testing on that includes security fixes if they are still testing a 7.3.x release that includes those same fixes but also has other fixes so testing is still on-going.It's a release candidate, so clearly testing is not entirely complete or it'd be a final.and if for some reason they cannot release 7.3.x release candidate at the same time, then they shouldn't disclose details about security vulnerabilities until such time that all releases are available - though that is hard when it's upstream packages, or if already disclosed - which is even more reason to get all the releases out.Reality is they should have held this RC until the 7.3.x RC was also ready... or if they were working on some other features that aren't ready yet, but needed to get this RC out, then they should have also rolled an interim RC for 7.3.x including the same security patches as 7.2.x. Edited July 25Jul 25 by warpspeed
July 25Jul 25 On 7/24/2026 at 4:06 AM, warpspeed said:From a security patch posture point of view, it's not a good look to remediate an older release and not the current release at the same time.Basically like announcing that 7.3.2 now has exploitable vulnerabilities that are not patched.This is why others generally release patches for all supported OS versions at once.Releases that include security fixes should ideally be done at the same time.iirc 7.3.2 already contained the critical security fixes in 7.2.8rc1.
July 25Jul 25 As far as I can tell, 7.3.2 was released first and this is the catch-up security release.
July 25Jul 25 That is correct; this is for updating packages for 7.2, which were already updated for 7.3.2
July 26Jul 26 11 hours ago, JorgeB said:That is correct; this is for updating packages for 7.2, which were already updated for 7.3.2Ahh that's interesting, and quite a gap the opposite way around then. My point still stands, it's just inverted. 7.2 should have seen a release at the same time as 7.3, with the same security patches. :)
July 27Jul 27 21 hours ago, warpspeed said:Ahh that's interesting, and quite a gap the opposite way around then. My point still stands, it's just inverted. 7.2 should have seen a release at the same time as 7.3, with the same security patches. :)Limited resources prevent instantaneous updates. (Limetech does do QA on all updates before they are released as a general release. Note that this a release candidate– that is what the rc means –so they are waiting to see if there are any problems are found by the early adopters before that general release.)
July 27Jul 27 2 hours ago, Frank1940 said:Limited resources prevent instantaneous updates. (Limetech does do QA on all updates before they are released as a general release. Note that this a release candidate– that is what the rc means –so they are waiting to see if there are any problems are found by the early adopters before that general release.)They don't have to do them instantaneous, what I'm saying is they should sync the releases, especially when it comes to security releases. If one is ready first, hold it back till the others are ready. Then push them all out at once.It will also help reduce confusion for those that are on older release trains that can't upgrade to the very latest, and those that are on the latest that don't understand the releases and scratch their heads wondering which release is the latest/best to be on.
July 27Jul 27 I get your point from a communication point of view.But at the same time, that means that systems are kept vulnerable for longer than necessary.It would be better to address the communication point via, well, communication. 😁A post with the reasoning beyond going for branch A rather than branch B would go a long way for most people. Sure, some users will always complain that " you should have prioritized the other branch because XYZ" but delaying is probably not a great solution overall.
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.