Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Backport PR 21364 into 4.6.x #21781

Closed
nazar-pc opened this issue Nov 5, 2024 · 5 comments
Closed

Backport PR 21364 into 4.6.x #21781

nazar-pc opened this issue Nov 5, 2024 · 5 comments

Comments

@nazar-pc
Copy link

nazar-pc commented Nov 5, 2024

#21364

Can we get this backported to v4.6.x branch given its security nature? Due to v5.0 requirements for Qt, new versions are not available in Ubuntu 24.04 (#21608 (comment)). I believe because of this, it warrants having security release for older branch. Leaving 24.04 out of support feels kinda cheap consider this is current LTS and released just few months ago.

Originally posted by @proton-ab in #21364 (comment)

@stalkerok
Copy link
Contributor

No.
IMO, Sharp Security's dirty PR at the expense of exaggerating a non-existent issue. Has nothing to do with security.

@ArcticGems
Copy link

ArcticGems commented Nov 6, 2024

No. IMO, Sharp Security's dirty PR at the expense of exaggerating a non-existent issue. Has nothing to do with security.

So Sharp Security's findings are wrong???

@nazar-pc
Copy link
Author

nazar-pc commented Nov 6, 2024

This is not the right place to debate whether the issue is real or not. The issue is quite obviously real and significant, or else it wouldn't be fixed.

The only remaining question is whether maintainers will backport the fix for Ubuntu LTS and similar distros or not. I personally hope they do, hence the issue, but it is up to them of course.

@stalkerok
Copy link
Contributor

So Sharp Security's findings are wrong???

The findings are very much exaggerated to make a name for themselves.

The issue is quite obviously real and significant, or else it wouldn't be fixed.

It's not significant.
You want security? Don't use the internet and don't download anything via torrent.

@xavier2k6
Copy link
Member

@sledgehammer999 Please contribute when free.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants