What is the protocol in regards to backporting security updates to ESR versions? In particular, dependency version updates. Our site is currently running on v2026.1.3, with an upgrade to v2026.7.2 happening soon. Looking at security scans and vulnerabilities being flagged, and cross-referencing package updates in monthly releases that resolve CVE’s, I’ve noticed updates that aren’t making it to the ESR version.
frye_bradley
(Bradley Frye)
62
Gerelateerde topics
| Topic | Antwoorden | Weergaven | Activiteit | |
|---|---|---|---|---|
| January 2026 Releases | 15 | 1531 | 3 februari 2026 | |
| July 2026 monthly release | 13 | 663 | 29 juli 2026 | |
| Stable branch compatibility with discourse_docker and plugins | 37 | 2964 | 3 februari 2024 | |
| Jumping from 2026.1 ESR to 2026.7 - What I found | 6 | 382 | 12 september 2026 | |
| Enable updates only to a given release | 28 | 3434 | 25 januari 2017 |