Live data from Hacker News

GitLab Major Security Update for CVE-2016-4340

about.gitlab.com

1–10 of 45 posts

Re: GitLab Major Security Update for CVE-2016-4340

#4
post #2

why do they release it at 5pm PDT? A lot of people are leaving work on the west coast. The rest of the country people are home eating dinner. EU is sleeping. Really stupid time.

Its probably the most convenient window to minimise service disruption amongst users of gitlabs.

Pretty common for security patches to take place out of hours

Re: GitLab Major Security Update for CVE-2016-4340

#5
post #3

No details, just like the posts about this yesterday. Obligatory 'check our blog later for more.'

It would be nice to know what versions are affected now but I can understand that they may not want to reveal that until it's patched to prevent any unauthorized access of private repositories.

Re: GitLab Major Security Update for CVE-2016-4340

#6
post #3

No details, just like the posts about this yesterday. Obligatory 'check our blog later for more.'

It would be nice to know what versions are affected now but I can understand that they may not want to reveal that until it's patched to prevent any unauthorized access of private repositories.

From an email they sent out two days ago:

  The following versions are affected:

    8.7.0
    8.6.0 through 8.6.7 
    8.5.0 through 8.5.11 
    8.4.0 through 8.4.9 
    8.3.0 through 8.3.8 
    8.2.0 through 8.2.4 
Not sure why this wasn't included here.

Re: GitLab Major Security Update for CVE-2016-4340

#7
post #2

why do they release it at 5pm PDT? A lot of people are leaving work on the west coast. The rest of the country people are home eating dinner. EU is sleeping. Really stupid time.

Here in AU, we're not comfortable with the proposition that security alerts should be delayed until it's convenient for where $SOMEONE_ELSE happens to live.

EDIT: Or, indeed, that security patches should be delayed at all.

Re: GitLab Major Security Update for CVE-2016-4340

#8
post #6

Earlier quoted context omitted.

It would be nice to know what versions are affected now but I can understand that they may not want to reveal that until it's patched to prevent any unauthorized access of private repositories.

From an email they sent out two days ago: The following versions are affected: 8.7.0 8.6.0 through 8.6.7 8.5.0 through 8.5.11 8.4.0 through 8.4.9 8.3.0 through 8.3.8 8.2.0 through 8.2.4 Not sure why this wasn't included here.

Is it a specific mailing list ? I didn't get anything.

Re: GitLab Major Security Update for CVE-2016-4340

#9
post #7
post #2

why do they release it at 5pm PDT? A lot of people are leaving work on the west coast. The rest of the country people are home eating dinner. EU is sleeping. Really stupid time.

Here in AU, we're not comfortable with the proposition that security alerts should be delayed until it's convenient for where $SOMEONE_ELSE happens to live. EDIT: Or, indeed, that security patches should be delayed at all.

You shouldn't think of this as being delayed; they are providing advance notice of a serious vulnerability being patched so that those using it can update ASAP.

Re: GitLab Major Security Update for CVE-2016-4340

#10
post #7
post #2

why do they release it at 5pm PDT? A lot of people are leaving work on the west coast. The rest of the country people are home eating dinner. EU is sleeping. Really stupid time.

Here in AU, we're not comfortable with the proposition that security alerts should be delayed until it's convenient for where $SOMEONE_ELSE happens to live. EDIT: Or, indeed, that security patches should be delayed at all.

Remind me where AU is again??
Post reply on HN