Where did you install Firefox from? Help Mozilla uncover 3rd party websites that offer problematic Firefox installation by taking part in our campaign. There will be swag, and you'll be featured in our blog if you manage to report at least 10 valid reports!

搜索 | 用户支持

防范以用户支持为名的诈骗。我们绝对不会要求您拨打电话或发送短信,及提供任何个人信息。请使用“举报滥用”选项报告涉及违规的行为。

Learn More

Delay in posting link to latest binary

  • 2 个回答
  • 0 人有此问题
  • 29 次查看
  • 最后回复者为 evit

more options

I've notice that the Mozilla Foundation Security Advisory page is very timely on release details of security fixed but the Thunderbird Release Notes and main download link are not.

When security patches are detailed here: https://www.mozilla.org/en-US/security/advisories/

Sometimes it is delayed DAYS before the updated binary is available for download on the main Thunderbird page https://www.thunderbird.net/en-US/ or shown in the changelog at https://www.thunderbird.net/en-US/thunderbird/releases/

What is that? Isn't that kind of a big issue?

I've notice that the Mozilla Foundation Security Advisory page is very timely on release details of security fixed but the Thunderbird Release Notes and main download link are not. When security patches are detailed here: https://www.mozilla.org/en-US/security/advisories/ Sometimes it is delayed DAYS before the updated binary is available for download on the main Thunderbird page https://www.thunderbird.net/en-US/ or shown in the changelog at https://www.thunderbird.net/en-US/thunderbird/releases/ What is that? Isn't that kind of a big issue?

所有回复 (2)

more options

Your question should go to developers for a detailed response, not here. Yet, from my own development experience, it takes time to confirm a fix to the time that all documentation is updated and the module is ready for deployment. There is a quality assurance effort in that time gap. I am not clear on what your expectations are.

more options

Got it. Thanks for the deets.

My expectations are that if they have a security advisory that states the new version fixes a vulnerability that I can find the updated binary. This is the case in nearly every open source project. I will take my question to them directly.