What is the protocol in regards to backporting security updates to ESR versions? In particular, dependency version updates. Our site is currently running on v2026.1.3, with an upgrade to v2026.7.2 happening soon. Looking at security scans and vulnerabilities being flagged, and cross-referencing package updates in monthly releases that resolve CVE’s, I’ve noticed updates that aren’t making it to the ESR version.
frye_bradley
(Bradley Frye)
62
Related topics
| Topic | Replies | Views | Activity | |
|---|---|---|---|---|
| January 2026 Releases | 15 | 1430 | February 3, 2026 | |
| July 2026 monthly release | 13 | 570 | July 29, 2026 | |
| Jumping from 2026.1 ESR to 2026.7 - What I found | 5 | 262 | July 29, 2026 | |
| Stable branch compatibility with discourse_docker and plugins | 37 | 2887 | February 3, 2024 | |
| Enable updates only to a given release | 28 | 3400 | January 25, 2017 |