This forum has been archived. All content is frozen. Please use KDE Discuss instead.
The Discussions and Opinions forum is a place for open discussion regarding everything related to KDE, within the boundaries of KDE Code of Conduct. If you have a question or need a solution for a KDE problem, please post in the apppropriate forum instead.

When will security patches for KDE 3.5 stop?

Tags: None
(comma "," separated)
RLucid
Registered Member
Posts
3
Karma
0
When will security patches for KDE 3.5 stop?

Have struggled to find an answer to this question, though have read some rather interesting threads, that search came up with. I do have vague memories, of some "statement" about future support, round about the time of the appeal to test KDE 4.0 beta, but I've forgotten and google returns speculation in forums rather than information.

Any rough ideas? How important are the distro KDE teams in this process?

Oviously binary updates will become progressively rarer, but may be "stuckist" users can expect enough info to work round, even if compile from source is beyond them.
pansz
Registered Member
Posts
113
Karma
0
OS
IMO security patches comes only from the basic system and kernel. KDE is a desktop environment, it is a high-level application suite and will update only for new version.

Security upgrades're for low-level system parts such as the kernel, the bin-utils, the X, the security algorithm, etc. There're never security updates for a desktop environment.

If there will be no KDE 3.5.11 or KDE 3.6.0, you can safely say the updates of KDE3 series have stopped already.

That is, my opinion, correct me if I'm wrong.
User avatar
JontheEchinda
KDE Developer
Posts
309
Karma
4
OS
Security problems can most certainly occur with high-level desktop applications. Recently, Amarok springs to mind: http://lists.grok.org.uk/pipermail/full ... 67330.html

That being said we're lucky in that most of KDE is secure. If we don't see any security updates, there would be a pretty good chance it's because no security holes have been found. :-)


JontheEchinda, proud to be a member of the Kubuntu team since July 2008.
Image
Image
RLucid
Registered Member
Posts
3
Karma
0
pansz wrote:IMO security patches comes only from the basic system and kernel. KDE is a desktop environment, it is a high-level application suite and will update only for new version.

In a network environment, that's not the case unfortunately security begins to affect every program using possibly "tainted" data on the system. You may need patches, without development of new features, and bumping a minor version number, might provoke re-compile and download of whole KDE. For example the non KDE Adobe Flash plugin gets it's regular fix. In KDE in past, Konqi, KDM and other parts have required attention.

Should (When?) some issue arises, at some point KDE team will be saying, "this is no longer our problem, as support ceased as announced here ...", really I'm trying to get an idea of when that really is.

Last edited by RLucid on Tue Jan 20, 2009 3:05 pm, edited 1 time in total.
User avatar
anda_skoa
KDE Developer
Posts
783
Karma
4
OS
My guess is that security updates will be available for at least a year or two.

The enterprise distributions (RHEL and SLED) ship with KDE3 and their next versions are yet to be released.

Additionally several consulting/service companies have KDE3 based products so they might also work on such fixes.

Cheers,
_


anda_skoa, proud to be a member of KDE forums since 2008-Oct.


Bookmarks



Who is online

Registered users: Bing [Bot], Google [Bot], Sogou [Bot]