Hacker News new | ask | show | jobs
by hoophoop 1896 days ago
FreedomBox is the only one that security updates from Debian. And for more than five years. Without breaking changes.
1 comments

Eh? People who installed Sandstorm in 2014 are still getting regular security auto-updates today, even if they haven't touched their server between then and now. The very first app package ever built for Sandstorm -- created before Sandstorm was even announced publicly -- still works today, on the latest version of Sandstorm.
No, there are no backports of security fixes for the applications.
Sandstorm's security model inherently mitigates most application security bugs.

That said, it's definitely true that Sandstorm's app library suffers from insufficient maintenance.