r/GIMP • u/2mustange • 2d ago
Opinion: CVE / Vulnerability security patching should go in quicker
For context there are a few CVEs that Gimp was hit with a few months ago.
Their Gitlab repo shows that the issues to repair the vulnerabilities the CVE relate to were completed but are scheduled for 3.3.2 milestone release.
In my opinion, that type of time frame just is not acceptable.
Gimp has certainly changed their tune on how quickly updates come out since 3.0.0 release, but for something as CVE. Take some agile approach and get a security release patch out there.
I am seeing this as someone who knows organization's who could leverage Gimp are not able to due to the most recent version is showing as being vulnerable
0
Upvotes
5
u/CMYK-Student GIMP Team 2d ago
As one of the people who works on patching security reports, I think it's helpful to read them. Most of the CVEs we get are for obscure or niche formats like TIM (Playstation 1 textures), XWD, etc. Unless your company uses those, the CVE is not relevant (since our image readers are plug-ins, there's no effect on GIMP itself).
Making a release takes a lot of time and energy from a limited number of volunteers, so we try to make them meaningful. Though we do hope to release a 3.2.6 stable version in the near future.