jsonparser icon indicating copy to clipboard operation
jsonparser copied to clipboard

Why were the patch versions for CVE-2020-10675 released so late?

Open Silence-worker-02 opened this issue 2 years ago • 0 comments

Hello, we are a research team working on Golang. During our investigation, we found CVE-2020-10675 was addressed in commit 91ac96899e492584984ded0c8f9a08f10b473717. However, we noticed that the patch version was released after long time (49 days). We are curious about the reasons behind the delayed release of the patch version, as it may hinder the efficient distribution of patches to downstream users. Could the reason be

1.Issues with testing and CI checking.

2.Other commits have to be incorporated into one release.

3.By convention, versions are not frequently released.

4.Other reasons.

Thank you for your attention, and we look forward to receiving your reply.

Silence-worker-02 avatar Jul 25 '23 08:07 Silence-worker-02