Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

openssl non-critical updates have been announced as coming May 28th #448

Closed
sam-github opened this issue May 23, 2019 · 5 comments
Closed

Comments

@sam-github
Copy link
Contributor

See: https://mta.openssl.org/pipermail/openssl-users/2019-May/010518.html

No CVEs are addressed. These are not security updates, so don't need to be handled as a security release.

  • 6.x: EOL, doesn't need updating
  • 11.x: EOL 4 days after expected release date, doesn't need updating
  • 8.x: will need update to 1.0.2s
  • 10.x, 12.x, and master: will need update to 1.1.1c

@nodejs/security @nodejs/security-release

@mhdawson
Copy link
Member

Do we think we can just roll them into the next planned release for each of the lines?

@richardlau
Copy link
Member

May 28th is the current revised date for 10.16.0. As it's non-critical I'd suggest releasing in the next planned 10.x release in mid-June.

@mhdawson
Copy link
Member

Do we think we can just roll them into the next planned release for each of the lines?

@sam-github
Copy link
Contributor Author

@mhdawson Yes, I think we can.

I opened this as a heads up, I'll have to open PRs directly onto the staging branches, since openssl updates don't merge backwards well.

Also, if someone wants an 11.x update, this would be the place to make the case for it.

@sam-github
Copy link
Contributor Author

nodejs/node#29445 is coming, this doesn't have to stay open.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants