Elektrine lite

← Feed

@jzb@hachyderm.io

2026-09-23 13:30 UTC

A user asked in a project forum, reasonably, "does the widely reported X security vulnerability that affects the project that this was forked from affect this project as well?" They were told, basically, that they should report such an issue in private. Um, no. Sorry - thats dumb. It's public knowledge that Project B is a fork of Project A from a specific version. If X security flaw affects A, then it's not exactly a big stretch for anybody to conclude that B may also be afflicted. It's not on users to quietly ask those developers "does that security hole affect us too?" It's already out there. If anything, it's a failure on the part of project B to not have made an announcement right away that either they are working on a fix (affected) or have concluded it's not an issue (not affected). It's rare that I feel like open-source maintainers owe anybody anything -- when it breaks, you get to keep both pieces and your money back! -- but don't chide people for asking an obvious question that you've failed to communicate about.

Replies (0)

No replies.