top | item 34583223

(no title)

mdeslaur | 3 years ago

https://wiki.ubuntu.com/SecurityTeam/FAQ#Official%20Support

discuss

order

cpncrunch|3 years ago

That doesn't really clarify things. It just says universe is supported by the community. Right now, we have an update for imagemagick, but we have to pay for it, whereas last year we had updates to imagemagick for free. How is that "best effort"? What they mean is, they are now putting more effort into universe, but you have to pay for the updates.

I don't mind having to pay for these updates if necessary. They should just be honest and transparent about what they are doing.

cpncrunch|3 years ago

Looking into this further, I see that Ubuntu 20.04 has an identical version of imagemagick to that on Debian 10. This is a security update to imagemagick from 2020:

https://launchpad.net/debian/+source/imagemagick/8:6.9.10.23...

There are no later versions of imagemagick on ubuntu 10. So, my guess is that Ubuntu has (and will continue to) take any security updates that appear in the upstream Debian release, and add an Ubuntu Universe package for them. Now, I'm guessing, there will be additional security updates in the Universe package set for users paying for Ubuntu pro, where those packages are not available on Debian (i.e. Ubuntu themselves will package them).

If that's the case then there is nothing nefarious going on, just Canonical didn't explain it very well.