Skip to content

Comment on Lessons from the Debian/OpenSSL Fiasco (2008)

Comments

I don't quite understand why would Debian keep their own forks of software and don't even attempt to upstream the changes. Is it just security backports to ensure "stability" by not actually updating the packages, or do they have other reasons for the changes?

Where do you get “don’t even attempt to upstream the changes” from? They absolutely try to in the common case, from what I’ve seen. Every delta from upstream carries a cost, and no one knows that better than package maintainers.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.