?
avatar RichardEb
RichardEb
5 Sep 2016

Joomla very often releases updates that fixes vulnerabilites and other security risks. Unfortunately this patches comes often with other changes and a version number increase. So sometimes some addons aren't supported by the new joomla version. So I have to wait sometimes days or weeks befor every extension is compatible with the new update. During this time the page is highly vulnerable.

So I think it would be good if there are LTS Versions that only get security patches so I can keep my pages safe without this risk of malfunction of my extensions.

(Sometimes a page get hacked before every extension is released in a compatible version. So I have to live either with a hacked page or a not working page because of the incompatible addons)

Votes

# of Users Experiencing Issue
1/1
Average Importance Score
5.00

avatar RichardEb RichardEb - open - 5 Sep 2016
avatar RichardEb RichardEb - change - 5 Sep 2016
The description was changed
avatar RichardEb RichardEb - edited - 5 Sep 2016
avatar RichardEb
RichardEb - comment - 5 Sep 2016

This is also what linux do. Every common distro has a fixed LTS version. In this version the version numbers normaly doesn't change to prevent version conflicts. But if there is an security issue there will be a patch released from the distro manager team.

avatar piotr-cz
piotr-cz - comment - 5 Sep 2016

I agree.
Sometimes it takes longer to adapt site to new Joomla release and during this time it's exposed to all vulnerabilities.

avatar Bakual
Bakual - comment - 5 Sep 2016

That's what we did some years ago and it didn't work well. We changed to SemVer and a release strategy that uses a strong backward compatibility.
For a patch release (which security releases are), there shouldn't be any issues with 3rd party extensions and you should be fine updating as soon as possible.
If extensions stop working after such an update, we either messed up something or the extension is written that badly that we just can't help it.

Did you happen to have issues with the recent patch/security releases?

avatar RichardEb
RichardEb - comment - 5 Sep 2016

I hadn't had any problems the last year. But I'm looking forward to have an unattended auto update function for joomla. I already discussed my idea @forum.joomla.org/viewtopic.php?f=706&t=933373 and the main argument against such a function was that every extension should be manually checked for compatibility before doing a joomla update. So I tried to solve this problem at first.

But if you tell me there aren't any version conflicts in minor updates I should be fine starting a feature request for an auto update function.

avatar brianteeman
brianteeman - comment - 5 Sep 2016

I am closing this. We already have a topic discussing releases - we dont need two

avatar brianteeman brianteeman - change - 5 Sep 2016
Status New Closed
Closed_Date 0000-00-00 00:00:00 2016-09-05 12:53:07
Closed_By brianteeman
avatar brianteeman brianteeman - close - 5 Sep 2016
avatar RichardEb
RichardEb - comment - 5 Sep 2016

Where is the topic? ID?

avatar brianteeman
brianteeman - comment - 5 Sep 2016

#11921

On 5 September 2016 at 13:58, RichardEb notifications@github.com wrote:

Where is the topic?


You are receiving this because you modified the open/close state.
Reply to this email directly, view it on GitHub
#11931 (comment),
or mute the thread
https://github.com/notifications/unsubscribe-auth/ABPH8cVtqLatmBB0Xvw-AUmW7ddHeOdOks5qnBICgaJpZM4J00Hu
.

Brian Teeman
Co-founder Joomla! and OpenSourceMatters Inc.
http://brian.teeman.net/

Add a Comment

Login with GitHub to post a comment