Re: Log4Shell impacts on ODL releases


Daniel de la Rosa
 

Hello Robert 

On Mon, Jan 10, 2022 at 5:42 AM Robert Varga <nite@...> wrote:
Hello everyone,

these winter holidays we got a present in the form of Log4Shell, which
affects pretty much all artifacts we have ever released.

As per our release lifecycle rules, this means that:

- all release trains up to and including Aluminium are past their End of
Life and will not be receiving a community-driven release

- Silicon is currently in its Security Support period past its last
scheduled Service Release, hence will receive an unscheduled
security-driven SR4 in near future

We can review this in the TSC but I think we can release Silicon SR4 after Phosphorus SR2 and before Sulfur. Thoughts? 
 

- Phosphorus is currently in its normal support period, hence will have
this (and other) issues resolved in the upcoming run-of-the-mill SR2

- Sulfur release train currently mirrors Phosphorus in the parts which
are affected, it will be updated at the same time and Sulfur GA will be
on par with Phosphorus SR2

Regards,
Robert





Join {TSC@lists.opendaylight.org to automatically receive all group messages.