develooper Front page | perl.perl5.porters | Postings from April 2020

Re: RFC: Proposed update to perlpolicy regarding security fixes

From:
hv
Date:
April 12, 2020 01:11
Subject:
Re: RFC: Proposed update to perlpolicy regarding security fixes
Message ID:
202004120028.03C0S3P17452@crypt.org
Steve Hay via perl5-porters <perl5-porters@perl.org> wrote:
:Recent discussions surrounding a fix for a security issue have revealed a
:shortcoming in some of the wording in perlpolicy.pod regarding what is
:acceptable for backporting to maint releases.
:
:The current wording, which dates back to when Jesse Vincent first added the
:whole maint policy section back in 2010, says that patches that add new
:warnings or errors are not acceptable, but makes no exception for security
:issues.
:
:The suggestion has been made that fixing security issues should take
:precedence over other considerations. I think this would be a sensible
:change to make, and have reworded perlpolicy slightly along these lines in
:the attached patch.

+1 from me.

Hugo



nntp.perl.org: Perl Programming lists via nntp and http.
Comments to Ask Bjørn Hansen at ask@perl.org | Group listing | About