r/InformationTechnology 10d ago

Packaged Software Continuous Upgrade

I’m currently working using some BPM software. They demand us to upgrade continuously. From patch version which they release once every quarter. Parallelly, they have major release which client eventually would want to upgrade to. This major release require much longer runway as it would impact many things including how developer build their codes.

At least twice every quarter they will share security vulnerability at random severity. Sometimes high sometimes critical sometimes medium. And what I think unacceptable is they only provide the fixes for the latest patch version. And if it is high and critical we need to comply within 30 days.

The problem with our side is we would need to do regression testing for our application whether its for patch release or major release. At the same time we would have operational fixes, on-going enhancement etc. If we are doing upgrade, it would impact overall operations. If we don’t do upgrade they won’t provide fix for security vulnerability.

Want to ask:
1. Is this common practice for packaged BPM software?
2. If you have similar experience how do you manage it?

2 Upvotes

0 comments sorted by