[fab] rant: why does it take so long to prepare a firefox update for FC5?

Thorsten Leemhuis fedora at leemhuis.info
Tue Aug 8 08:22:26 UTC 2006


Hi!

<make noise mode>
<rant>
Firefox 1.5.0.5 was released on July 26, nearly two weeks ago now. It 
contains very important security fixes AFAICS (an exploit is in the wild 
AFAIK) but there is still no update for FC5 in sight. What the heck is 
taking so long? This behavior brings Fedora in discredit because Firefox 
is a very important package. And it's actually the second time already 
that it takes so long -- firefox 1.5.0.4 was release as FC5 update on 15 
Jun 2006, two weeks after the official release on mozilla.org.

This really sucks.
</rant>

Some background details follow:

Fixes in Firefox 1.5.0.5:
http://www.mozilla.org/security/announce/

Our bug, opened 2006-07-27 00:27 EST:
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=200357

Link to public CVS; updated Firefox was checked in there some days ago, 
but no new packages showed up yet on the servers AFAICS
http://cvs.fedora.redhat.com/viewcvs/rpms/firefox/FC-5/

RHEL Fix (rated Critical, published Fri, 28 Jul 2006 20:16:50 -0400)
http://www.redhat.com/archives/enterprise-watch-list/2006-July/msg00021.html

Firefox 1.5.0.4 update for FC5:
https://www.redhat.com/archives/fedora-package-announce/2006-June/msg00106.html

Firefox 1.5.0.4 notes (released June 1, 2006)
http://www.mozilla.com/firefox/releases/1.5.0.4

</make noise mode>

CU
thl




More information about the advisory-board mailing list