Skip to content

Why were the patch versions for CVE-2021-28484 released so late? #48

@Silence-worker-02

Description

@Silence-worker-02

Hello, we are a research team working on Golang. During our investigation, we found CVE-2021-28484 was addressed in commit 82bdf20. However, we noticed that the patch version (v3.0.1) was released after long time (30 days). We are curious about the reasons behind the delayed release of the patch version, as it may hinder the efficient distribution of patches to downstream users. Could the reason be

1.Issues with testing and CI checking.

2.Other commits have to be incorporated into one release.

3.By convention, versions are not frequently released.

4.Other reasons.

Thank you for your attention, and we look forward to receiving your reply.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions