

























For quite a while, OBS Studio used a very insecure version of the Chromium Embedded Framework. The Fedora package updates that much more frequently.
The same goes with Qt, though the risk is lower. The only way I know to have an LTS version of Qt is to buy the paid version. Otherwise you need to update monthly to get security fixes.
Sometimes updates introduce bugs, but in those cases you have to choose between bugs or a risk of getting compromised. Distro maintainers I know tend to prefer the former.
The proper solution is to test with pre-release versions of dependencies, and either fix any regressions upstream or work around them. This ensures that one can update to the next release without problems. However, I’m not aware of widely used projects that do this.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。