TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ubuntu Security Updates Are a Confusing Mess

88 点作者 popey10 个月前

11 条评论

captn3m010 个月前
I maintain <a href="https:&#x2F;&#x2F;endoflife.date&#x2F;ubuntu" rel="nofollow">https:&#x2F;&#x2F;endoflife.date&#x2F;ubuntu</a>. Ubuntu security policies are indeed a hot mess, and opaquely documented on their own website. I use it as an example of how not to document your support policies at <a href="https:&#x2F;&#x2F;endoflife.date&#x2F;recommendations" rel="nofollow">https:&#x2F;&#x2F;endoflife.date&#x2F;recommendations</a>.<p>At one point Ubuntu changed the EOL tables on their Wiki from 5 years to 10 with no explanation about applicability&#x2F;ESM - just calling it LTS.<p>It is among the longest pages on our website.
frankjr10 个月前
I don&#x27;t care they&#x27;re gating this behind a subscription but the fact that they won&#x27;t even tell you that you&#x27;re missing an important security update? That&#x27;s bad. I wonder how many people think they are fully up to date while being vulnerable to known bugs.
评论 #40940982 未加载
评论 #40941243 未加载
hs8610 个月前
Most Ubuntu users don&#x27;t know that Canonical only supports the main repository for free.<p>To my knowledge, only some comments hidden in &#x2F;etc&#x2F;apt&#x2F;sources.list mention this, but the more honest approach would be to warn all users when they try to `apt install foo` some package from universe&#x2F;multiverse. Or do it like RHEL with their EPEL repo and disable it by default.<p>But I guess they would have never gotten this popular if people saw that Ubuntu is only a few thousand packages compared to Debian&#x27;s tens of thousands.
n3storm10 个月前
Ubuntu is reselling Debian, once they made it well, now I don&#x27;t know
评论 #40941764 未加载
thinkst10 个月前
The updates in universe are definitely best effort.<p>We were paying for Ubuntu Pro through an AWS subscription on 2k EC2 instances, and could not get Canonical to update a package with a CVSS 7.8 in the 18.04 LTS.<p>We&#x27;ve moved off Ubuntu Pro as a result. Blogged it at <a href="https:&#x2F;&#x2F;blog.thinkst.com&#x2F;2024&#x2F;07&#x2F;unobtrusively-upgrading-ubuntu-underfoot.html" rel="nofollow">https:&#x2F;&#x2F;blog.thinkst.com&#x2F;2024&#x2F;07&#x2F;unobtrusively-upgrading-ubu...</a>
arjvik10 个月前
If I was looking for a distro with paid support (a la RHEL&#x2F;Ubuntu) that&#x27;s also not incredibly behind bleeding edge (maybe not as bleeding edge as Arch, but also not running patched-to-hell-and-back software like Ubuntu), what are my options?<p>Thankfully I&#x27;m not personally looking for this at the moment, I&#x27;m more than happy being my own sysadmin and running anything from Arch to Fedora CoreOS to OpenSUSE on my machines.
评论 #40940879 未加载
评论 #40941107 未加载
评论 #40940930 未加载
评论 #40940952 未加载
BeefySwain10 个月前
&gt; ...what are my options? &gt; ...Maybe it is time to go back to Debian, as they seem to release these fixes to their users?<p>Curious if this would actually be a solution. They state that fixes in Debian are down-streamed regardless of support, so if this fix wasn&#x27;t down-streamed, then why would it be in Debian ?
评论 #40945420 未加载
bravetraveler10 个月前
I&#x27;d argue we wouldn&#x27;t have Snap <i>[for the better]</i> if their LTS releases weren&#x27;t <i>visually</i> bound to years... saving overhead they regularly create for cosmetic reasons.<p>Wouldn&#x27;t have to create it to consolidate platforms if they stopped making them so often!<p>They have three concurrent LTS releases when they need one. <i>Maybe</i> two. 18.04 is the python2 of distributions. Let it go.<p>Having worked in several places that relied on it... ESM is being the bad kind of enabler.<p>Fedora handles <i>&quot;The Snap Problem&quot;</i> -- many target distributions -- with &#x27;fedpkg&#x27; and &#x27;mock&#x27;. Software and machines <i>on the build side</i>. Not by degrading the end user experience. They do participate with Flatpak... but that&#x27;s peer pressure more than anything.<p>Flatpak is more well-rounded IMO. Probably from being the broader answer. Maybe this all doesn&#x27;t make an argument. Just a bunch of statements. I don&#x27;t know.<p>Back on topic: I wonder what all of this Canonical stuff in particular is for&#x2F;leads to. New software isn&#x27;t scary; &#x27;just&#x27; plan&#x2F;test. It becomes scary when you get lazy here... so accept your involvement.
评论 #40941581 未加载
markshuttle10 个月前
Your free personal Ubuntu Pro subscription does in fact cover as many VMs and containers as you can run on up to five personal machines, as the OP well knows. I like that we make Ubuntu Pro, including universe updates, free for anyone running at small scale.
评论 #40947515 未加载
cosmin80010 个月前
<i>Ubuntu is a mess</i>, there you go I fixed your title, joke but no joke, is real.
Suppafly10 个月前
Is it not possible to fix the one package from the debian sources vs waiting for ubuntu to allow him to get it from them?
评论 #40940873 未加载
评论 #40941065 未加载