envoyproxy / envoyproxy/envoy

Cadence of security release does not match documentation

Open
#25,559 3 comments 0 reactions 0 assignees View on GitHub
area/release area/security enhancement help wanted
Dominant language
C++
Stars
28.9k
Forks
5.6k
Avg merge
1d 20h
Merged PRs (30d)
437

Description

It takes a lot of hard for from volunteers on the security team to put out a security release. The documentation in RELEASES.md suggest that security releases will happen quarterly. However the most recent security release was in June of 2022, which was 8 months ago. This leave the project in a position where there are open security bugs which have been unreleased for 9 months. This is not ideal.

This was discussed at the most recent Envoy Community meeting. The core issue seems to be that running the security release is a volunteer position. It seems likely that unless someone is hired specifically for this purpose, we will continue to see long periods between release. There were a couple of proposal for how to mitigate this situation.

* Only kick off a security release for Critical or High impact issues.
* Only backport fixes to the most recent stable branch

It would be a good idea to get consensus within the project for how we'd like to handle this.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.