In general, Drupal core releases are created whenever there is a major security issue.
What is the Drupal Core Release Process?
The process goes something like this:
- Vulnerability is identified (internally or externally) and the security team learns of it
- Depending on the severity of the issue and the complexity of fixing it, people set about to fix it
- repeat steps 1 and 2 until there is a critical mass of issues that make it worthwhile to create a release. An exploit in the wild (if that ever were to happen) also triggers a release
- Make a release (which is much more work than those 3 little words make it seem)
How Many Drupal Core Releases Have Their Been in 2008?
There are people who feel that there have been too many releases for Drupal 6.x, that they happen "every two weeks" according to a recent comment. What is the reality?
- 6.8 December 11, 2008 - 17:55 (not a security release)
- 6.7 December 10, 2008 - 22:31
- 6.6 October 22, 2008 - 19:27
- 6.5 October 8, 2008 - 20:15
- 6.4 August 14, 2008 - 00:05
- 6.3 July 9, 2008 - 21:53
- 6.2 April 9, 2008 - 21:15
- 6.1 February 27, 2008 - 19:51
- 6.0 February 13, 2008 - 14:29
Especially if you eliminate the December 11 release which was only important to people using old versions of PHP, there have been fewer than 1 release per month since the beginning of the 6.x series.
What is the Cost of a Security Release to a Site Admin?
For an inexperienced person an upgrade might take a half an hour if it goes well. For an experienced Drupal or system administrator it takes a few minutes.
So, is that too much? Too little? How do those numbers compare to other platforms?
Comments
Post new comment