Re: PostgreSQL 11.1, 10.6, 9.6.11, 9.5.15, 9.4.20, and 9.3.25 Released!

From: "Jonathan S(dot) Katz" <jkatz(at)postgresql(dot)org>
To: Michael Banck <michael(dot)banck(at)credativ(dot)de>, pgsql-advocacy(at)lists(dot)postgresql(dot)org
Subject: Re: PostgreSQL 11.1, 10.6, 9.6.11, 9.5.15, 9.4.20, and 9.3.25 Released!
Date: 2018-11-09 14:18:17
Message-ID: 7f58a703-e810-95d2-489a-06d1788cd357@postgresql.org
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-advocacy pgsql-announce

Hi Michael,

On 11/9/18 4:45 AM, Michael Banck wrote:
>
> AIUI, this security issue only affects v10 and v11, but this is not
> clear from the announcement AFAICT, unless I missed it?
>
> I think it would be good to mention the exact versions that are affected
> by a CVE in the announcement; of course it is always possible to inspect
> the individual release notes, but having the information up front would
> be nice (again, unless I am missing something).

That is a fair point. I have looked through the past few announcements
and we have not included affected versions, just links to the CVE, which
do detail the versions available as well as the release notes which you
mention above. It probably would have helped to do that, and I look into
updating it on the website at a minimum.

That said, when I was drafting the announcement, it was becoming a bit
convoluted to craft clear instructions based on the security release +
additional upgrade steps for pg_stat_statements. I opted for keeping it
simple.

And there is still a problem of people not upgrading to the latest bug
fix releases. If there is language or motivation to continue to stay on
the point releases, personally I'd prefer to encourage that.

Thanks!

Jonathan

In response to

Responses

Browse pgsql-advocacy by date

  From Date Subject
Next Message Jonathan S. Katz 2018-11-09 14:27:43 Re: PostgreSQL 11.1, 10.6, 9.6.11, 9.5.15, 9.4.20, and 9.3.25 Released!
Previous Message Michael Banck 2018-11-09 09:45:16 Re: PostgreSQL 11.1, 10.6, 9.6.11, 9.5.15, 9.4.20, and 9.3.25 Released!

Browse pgsql-announce by date

  From Date Subject
Next Message Jonathan S. Katz 2018-11-09 14:27:43 Re: PostgreSQL 11.1, 10.6, 9.6.11, 9.5.15, 9.4.20, and 9.3.25 Released!
Previous Message Daniele Varrazzo 2018-11-09 11:50:15 Psycopg 2.7.6 released