Buildroot Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Julien Olivain via buildroot <buildroot@buildroot.org>
To: Franciszek Stachura <fbstachura@gmail.com>
Cc: buildroot@buildroot.org
Subject: Re: [Buildroot] [PATCH] package/memcached: security bump version to 1.6.45
Date: Sat, 15 Aug 2026 11:12:34 +0200	[thread overview]
Message-ID: <574be64001fb9f9b38f833a41106bf43@free.fr> (raw)
In-Reply-To: <20260814190051.2970501-2-fbstachura@gmail.com>

Hi Franciszek,

On 14/08/2026 21:00, Franciszek Stachura wrote:
> https://github.com/memcached/memcached/wiki/ReleaseNotes1644
>> Hot on the heels of the last security release is...
>> another security release
> 
> https://github.com/memcached/memcached/wiki/ReleaseNotes1645
>> So this is a lot of crash and security bugs.
> 
> Signed-off-by: Franciszek Stachura <fbstachura@gmail.com>

Applied to master, thanks.

> ---
> I'm wondering, are packages in Buildroot master supposed to be
> bleeding-edge? The maintainer also left this in the release notes:
> 
>> If you decide to deploy this please be cautious; use a canary server
>> and let it bake, just in case.
> 
> That said, 1.6.45 was released a month ago and I don't see any critical
> bugs reported in Github issues. (there are two AI-generated reports, 
> one
> is not considered a security issue, the POC of the other does not 
> work).

I don't think there is a general rule to whether have or not packages
using bleeding-edge versions in Buildroot master branch. This depends
a bit on the upstream package itself, and it's also a up to the
Buildroot package maintainer.

The general rules I would give would be to try to keep package versions
that works in Buildroot (for all cpu architectures, gcc versions, with
dependencies too, ...), and avoid using intermediate development
version which are updated too often or too unstable.

Some packages, like Wine for example, decided to use
only stable versions:
https://gitlab.com/buildroot.org/buildroot/-/blob/master/package/wine/wine.mk#L7

Best regards,

Julien.
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

  reply	other threads:[~2026-08-15  9:12 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-14 19:00 [Buildroot] [PATCH] package/memcached: security bump version to 1.6.45 Franciszek Stachura
2026-08-15  9:12 ` Julien Olivain via buildroot [this message]
2026-08-22 12:31 ` Titouan Christophe via buildroot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=574be64001fb9f9b38f833a41106bf43@free.fr \
    --to=buildroot@buildroot.org \
    --cc=fbstachura@gmail.com \
    --cc=ju.o@free.fr \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox