• ZoteTheMighty@lemmy.zip
    link
    fedilink
    arrow-up
    6
    ·
    edit-2
    13 hours ago

    For package maintainers, it’s reasonable to expect security updates are rolled out the same week that a vulnerability is found. If you can’t deploy a new version of a package in 6 months, not maintaining the package is also a valid option.