The Artima Developer Community
Sponsored Link

Python Buzz Forum
Urgent! Upgrade now and don't ask questions

0 replies on 1 page.

Welcome Guest
  Sign In

Go back to the topic listing  Back to Topic List Click to reply to this topic  Reply to this Topic Click to search messages in this forum  Search Forum Click for a threaded view of the topic  Threaded View   
Previous Topic   Next Topic
Flat View: This topic has 0 replies on 1 page
Carlos de la Guardia

Posts: 219
Nickname: cguardia
Registered: Jan, 2006

Carlos de la Guardia is an independent web developer in Mexico
Urgent! Upgrade now and don't ask questions Posted: Aug 10, 2006 8:47 PM
Reply to this message Reply

This post originated from an RSS feed registered with Python Buzz by Carlos de la Guardia.
Original Post: Urgent! Upgrade now and don't ask questions
Feed Title: I blog therefore I am
Feed URL: http://blog.delaguardia.com.mx/feed.atom
Feed Description: A space to put my thoughts into writing.
Latest Python Buzz Posts
Latest Python Buzz Posts by Carlos de la Guardia
Latest Posts From I blog therefore I am

Advertisement

Rails developers got a little flak these days because they discovered a security problem with Rails and promptly published a patch for its users, but without saying what it did or which vulnerability it fixed, because they thought it was too critical to tell.

Open source and free software projects traditionally favor immediate and full disclosure of security issues, so many developers seem to have felt a betrayal of sorts when the Rails team refused to specify the details (or even the gist) of the flaw. It didn't help that a new patch had to be released the next day because the original one didn't solve the issue completely.

To their credit, they created the patches very quickly and responded to the community as they usually do, but it has to be admitted that their handling of the situation was a little awkward.

Some say that the posture they assumed could jeopardize Rails' future on the enterprise, but I think they overreact. Rails has been growing very fast for two years and you have to expect some growing pains in a process which has been far more successful than problematic.

Even so, young web frameworks, like Django are looking at this incident to learn and decide how to deal with these problems when they face them in the future (they already had a security policy outlined on their site, which means they had put some thought on the problem before this).

In the Zope world, we are so used to the security hot fixes that come from time to time (which are posted on various mailing lists and feeds), that the announcement of one seldom causes discussion. These are the signs of maturity of a project that sometimes go unnoticed.


Read: Urgent! Upgrade now and don't ask questions

Topic: [Aug 9, 2006 10:13 PDT] 1 Links Previous Topic   Next Topic Topic: Not all dynamic languages are equally dynamic

Sponsored Links



Google
  Web Artima.com   

Copyright © 1996-2019 Artima, Inc. All Rights Reserved. - Privacy Policy - Terms of Use