|
|
|
|
|
by Lerc
16 days ago
|
|
Would you hold off on fixing a security vulnerability if it caused a limited regression? Regressions should be fixed expediently, but if you apply the criteria "need to not happen" they are literally blocking issues. They could then block security fixes. |
|
I worked on major OSS projects and we never just blindly pushed out untested poor quality code for security fixes since that adds WORSE security regressions.