Re: Problem with OpenSCG downloads

From: Jim Mlodgenski <jimmy76(at)gmail(dot)com>
To: Magnus Hagander <magnus(at)hagander(dot)net>
Cc: Bruce Momjian <bruce(at)momjian(dot)us>, Andres Freund <andres(at)anarazel(dot)de>, Justin Clift <justin(at)postgresql(dot)org>, PostgreSQL www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Problem with OpenSCG downloads
Date: 2018-08-17 12:35:28
Message-ID: CAB_5SReojXhjUU6dN2wn2zZ+gnXpY5fv=T7kWPBHVPLGb7JG_Q@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers pgsql-www

On Fri, Aug 17, 2018 at 3:48 AM, Magnus Hagander <magnus(at)hagander(dot)net>
wrote:

>
>
> On Fri, Aug 17, 2018 at 4:39 AM, Bruce Momjian <bruce(at)momjian(dot)us> wrote:
>
>> On Thu, Aug 16, 2018 at 09:25:36AM -0700, Andres Freund wrote:
>> > On 2018-08-16 16:32:00 +0100, Justin Clift wrote:
>> > > On 2018-08-16 16:25, Andres Freund wrote:
>> > > > FWIW, I find this pretty damning given that there's been new
>> security
>> > > > release for a week: You've added no notes about it to the bigsql
>> > > > download page. Pinged nobody, to get the downloadlinks temporarily
>> > > > adorned with a warning on the pg site. And then there's the issue
>> that
>> > > > the dates besides the releases on the download page are referencing
>> the
>> > > > date of the newest set of minor releases, but aren't actually new.
>> > > >
>> > > > This is ridiculously intransparent.
>> > >
>> > > Is it fairly simple for us to just comment out/remove the links for
>> now?
>> > >
>> > > We don't want to be pointing people to software with known security
>> issues.
>> > >
>> > > We can put the links back in when the updated downloads are in place.
>> :)
>> >
>> > Probably don't want to remove them entirely, it might prevent people
>> > from upgrading from an even older release with more serious issues. But
>> > a red warning seems appropriate.
>>
>> Agreed. We need to do something _now_, and the fact that we are having
>> to discover this instead of OpenSCG telling us is a good reason to
>> suspect the use of this download site in the future.
>>
>> Looking at their website now, does it show they now have the proper
>> binaries?
>>
>> https://www.openscg.com/bigsql/postgresql/installers/
>>
>> PostgreSQL 10.5 - Stable (09-Aug-18)
>>
>> postgresql-10.5-win64.exe
>> postgresql-10.5-osx64.dmg
>>
>>
> Per the filenames it looks like they do. But the dates are still backdated
> on them?
>
> Jim, any confirmation on the status?
>
>
Yes, we pushed the latest installers last night.

The reason for the back date is because we did post new binaries on Aug-9,
but didn't post the new installers until last night. That meant that
existing users of the installers would get the latest updates posted on
Aug-9 if they checked for updates through the mechanism of their existing
install. Also, if new users installed the older version, at the end they
would see there are updates available if they checked. The server we used
to wrap the installers was down which caused the delay.

Sorry for the trouble and we'll be much more proactive of letting everyone
know if we have any difficulty in the future which I don't anticipate
happening.

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Magnus Hagander 2018-08-17 12:48:00 Re: Problem with OpenSCG downloads
Previous Message Bruce Momjian 2018-08-17 12:34:28 Re: Problem with OpenSCG downloads

Browse pgsql-www by date

  From Date Subject
Next Message Jan Karremans 2018-08-17 12:39:43 Re: Edit rights for a user
Previous Message Bruce Momjian 2018-08-17 12:34:28 Re: Problem with OpenSCG downloads