# 安全配置论坛升级到稳定版本的方法？

**URL:** <https://meta.discourse.org/t/secure-way-to-configure-upgrading-to-only-stable-version-of-forum-releases/292645>\
**Category:** Self-hosting\
**Tags:** stable\
**Created:** [2024年一月23日 15:34 UTC](https://meta.discourse.org/t/secure-way-to-configure-upgrading-to-only-stable-version-of-forum-releases/292645 "2024-01-23T15:34:42Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![ariznaf](https://avatars.discourse-cdn.com/v4/letter/a/ecccb3/32.png) [@ariznaf](https://meta.discourse.org/u/ariznaf)\
**Post date:** [2024年一月23日 15:34 UTC](https://meta.discourse.org/t/secure-way-to-configure-upgrading-to-only-stable-version-of-forum-releases/292645/1 "2024-01-23T15:34:43Z")

</div>

我们长期以来一直在使用 discourse 的默认 tests-passed 版本。

我想将论坛配置为仅使用稳定版本，并且每年只进行几次升级。

我已经阅读了如何配置 stable 分支的 app.yml 来使用 version: stable。

但我的顾虑是，我是否可以在任何时候安全地进行此操作，更改它并重建论坛。  
我们目前使用的是当前的 Beta5 版本，我担心它可能在数据库或从上一个稳定版本开始的其他部分进行了某些破坏性更改。

我可以在任何时候进行操作，还是必须等待下一个稳定版本？

我现在无法像以前那样投入大量时间来管理论坛，因此我希望每年只进行几次升级。

感谢您的指导。

---

<div class="post-metadata">

**Author:** ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)\
**Post date:** [2024年一月23日 16:08 UTC](https://meta.discourse.org/t/secure-way-to-configure-upgrading-to-only-stable-version-of-forum-releases/292645/2 "2024-01-23T16:08:56Z")

</div>

> [@ariznaf](#):
>
> 我可以在任何时候做吗，还是必须等到下一个稳定版本？

你必须等到下一个稳定版本（可能下周）。

---

<div class="post-metadata">

**Author:** ![ariznaf](https://avatars.discourse-cdn.com/v4/letter/a/ecccb3/32.png) [@ariznaf](https://meta.discourse.org/u/ariznaf)\
**Post date:** [2024年一月23日 16:12 UTC](https://meta.discourse.org/t/secure-way-to-configure-upgrading-to-only-stable-version-of-forum-releases/292645/3 "2024-01-23T16:12:58Z")

</div>

非常感谢，我将等到宣布稳定版本。

所以正确的方法是不再进行任何升级，等到宣布稳定版本，一旦宣布，将 `app.yml` 更改为 `version: stable` 并重建论坛。

这是正确的吗？

谢谢。

---

<div class="post-metadata">

**Author:** ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)\
**Post date:** [2024年一月23日 16:29 UTC](https://meta.discourse.org/t/secure-way-to-configure-upgrading-to-only-stable-version-of-forum-releases/292645/4 "2024-01-23T16:29:35Z")

</div>

![](https://media.tenor.com/YKixqyoR1xoAAAAC/thumbs-up-good.gif)

---

<div class="post-metadata">

**Author:** ![maaatt](https://avatars.discourse-cdn.com/v4/letter/m/ecb155/32.png) [@maaatt](https://meta.discourse.org/u/maaatt)\
**Post date:** [2024年一月31日 10:13 UTC](https://meta.discourse.org/t/secure-way-to-configure-upgrading-to-only-stable-version-of-forum-releases/292645/5 "2024-01-31T10:13:10Z")

</div>

@ariznaf @RGJ 请问您能帮我理解如何仅部署稳定版本或特定的 git 标签吗？（例如：3.1.4）

---

<div class="post-metadata">

**Author:** ![rahim123](https://avatars.discourse-cdn.com/v4/letter/r/df705f/32.png) [@rahim123](https://meta.discourse.org/u/rahim123)\
**Post date:** [2024年二月2日 11:38 UTC](https://meta.discourse.org/t/secure-way-to-configure-upgrading-to-only-stable-version-of-forum-releases/292645/6 "2024-02-02T11:38:55Z")

</div>

我和 OP 处于同样的情况。抱歉问了这么愚蠢的问题，但哪个是稳定发布版本？3.2.0 是“稳定”版本，对吧？

> [@3.2.0: Major Release](https://meta.discourse.org/t/3-2-0-major-release/293493):
>
> Discourse 3.2 is complete! This release includes significant improvements to chat, new AI powered features, and many updates for admins and moderators. We’ve completed the 3.2.0 development cycle and pushed out the final release. Check out our blog post, as well as all the 3.2.0.betaX #release-notes topics for details.

但同时也有一个 3.1.5 稳定版本：

> [@3.1.5: Security and bug fix release](https://meta.discourse.org/t/3-1-5-security-and-bug-fix-release/293094):
>
> Discourse 3.1.5 Stable Release Discourse strongly recommends that all sites follow the default tests-passed branch of Discourse. The “stable” branch is more focused on lack of change than lack of bugs - all releases, including those on tests-passed and beta are production ready. Security Updates This release includes fixes for this security issue reported by our community and [HackerOne](https://hackerone.com/discourse). Improperly sanitized user input leads to XSS [(CVE-2024-23834)](https://github.com/discourse/discourse/security/advisories/GHSA-rj3g-8q6p-63pc)

---

<div class="post-metadata">

**Author:** ![Firepup650](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/firepup650/32/465200_2.png) [@Firepup650](https://meta.discourse.org/u/Firepup650)\
**Post date:** [2024年二月2日 13:59 UTC](https://meta.discourse.org/t/secure-way-to-configure-upgrading-to-only-stable-version-of-forum-releases/292645/7 "2024-02-02T13:59:37Z")

</div>

有“tests-passed”（3.2.0 版本）和“stable”分支。虽然两者都“稳定”，但 stable 分支是：

> [@3.1.5：安全和错误修复版本，post:1](#):
>
> 更侧重于_缺乏变化_而不是_缺乏错误_

关于两者都“稳定”的说明：

> [@3.1.5：安全和错误修复版本，post:1](#):
>
> 所有版本，包括 tests-passed 和 beta 上的版本，都已准备好投入生产。

---

<div class="post-metadata">

**Author:** ![rahim123](https://avatars.discourse-cdn.com/v4/letter/r/df705f/32.png) [@rahim123](https://meta.discourse.org/u/rahim123)\
**Post date:** [2024年二月2日 17:27 UTC](https://meta.discourse.org/t/secure-way-to-configure-upgrading-to-only-stable-version-of-forum-releases/292645/8 "2024-02-02T17:27:34Z")

</div>

您好，感谢您的回复。是的，我理解关于“稳定=不变”与“稳定=不崩溃”之间的细微差别。但我感到困惑，因为我使用的是 `tests-passed`，它已经给我安装了 3.3.0.beta1-dev。我原以为 3.2.0 是最新的稳定版本，因为它名称中没有 `-dev` 或 `-beta`。现在看来，我是否必须等待整个 3.3.0 的开发周期，并且直到 `stable` 也达到 3.3.0 版本后，我才能切换到 `stable`？

---

<div class="post-metadata">

**Author:** ![JammyDodger](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jammydodger/32/254611_2.png) [@JammyDodger](https://meta.discourse.org/u/JammyDodger)\
**Post date:** [2024年二月2日 22:43 UTC](https://meta.discourse.org/t/secure-way-to-configure-upgrading-to-only-stable-version-of-forum-releases/292645/9 "2024-02-02T22:43:12Z")

</div>

3.2.0 确实是最新的 `stable` 版本。👍 如果您这次未能成功更换车道，则需要等到 3.3.0 完成（大约在七月下旬）后才能再次尝试。

不过，即使在 `tests-passed` 上，您也可以坚持在次要版本发布时进行更新，这也许会有帮助？

---

<div class="post-metadata">

**Author:** ![ariznaf](https://avatars.discourse-cdn.com/v4/letter/a/ecccb3/32.png) [@ariznaf](https://meta.discourse.org/u/ariznaf)\
**Post date:** [2024年二月5日 13:20 UTC](https://meta.discourse.org/t/secure-way-to-configure-upgrading-to-only-stable-version-of-forum-releases/292645/10 "2024-02-05T13:20:37Z")

</div>

由于我从未这样做过，所以我无法说出正确的方法。

我的理解是，您必须停止从非稳定版本升级系统，并等待比您当前版本更靠前的稳定版本。

然后编辑app.yml文件，并将其编辑为使用稳定版本而不是tests-passed。

然后执行完整的升级。

如果我的理解没错，目前还没有3.2.0稳定版本。

宣布的是3.2.0-beta5，所以未来可能很快就会有。

我现在安装的是3.2.0-beta5-dev (67244a2318)。

在哪里可以看到已发布的稳定分支版本？

编辑：我必须纠正，似乎3.2.0已经发布，并且与3.2.0-beta5是同一个版本。

---

<div class="post-metadata">

**Author:** ![ariznaf](https://avatars.discourse-cdn.com/v4/letter/a/ecccb3/32.png) [@ariznaf](https://meta.discourse.org/u/ariznaf)\
**Post date:** [2024年二月6日 19:26 UTC](https://meta.discourse.org/t/secure-way-to-configure-upgrading-to-only-stable-version-of-forum-releases/292645/11 "2024-02-06T19:26:07Z")

</div>

我已从 3.2.0-beta5-dev (test-passed) 更新到 3.2.0 stable，没有任何问题。

只需停止论坛，编辑 app.yml 并取消注释行 #version: test-passed，然后将其更改为 version: stable。

然后运行以下命令：

```plaintext
git pull
launcher rebuild app

```

等待重建过程结束，一切正常，现在它正在运行 3.2.0 stable 版本。

感谢所有提供的帮助。

---

<div class="post-metadata">

**Author:** ![system](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/system/32/443519_2.png) [@system](https://meta.discourse.org/u/system)\
**Post date:** [2024年三月7日 19:26 UTC](https://meta.discourse.org/t/secure-way-to-configure-upgrading-to-only-stable-version-of-forum-releases/292645/12 "2024-03-07T19:26:28Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
