ok, why did Arch not upgrade to Openssl 3 until after the vuln was patched? did they know about it before it was publicly disclosed or were warned not to upgrade or something?
known compiler nerd. jewish, ws71. i'm a maintainer of RustPython (bit less active though cause of ✨burnout✨) and i like open source and rust in general
ok, why did Arch not upgrade to Openssl 3 until after the vuln was patched? did they know about it before it was publicly disclosed or were warned not to upgrade or something?
Looks like it might've just taken a really long time to get everything working for OpenSSL 3? https://bbs.archlinux.org/viewtopic.php?id=277577