Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

I don't see the point of publishing a security bulletin if you are not going to timely push the fix to artifacts on all affected platforms. Tailscale needs to do better on their release process, docker hub shows last update was 8 days ago.


I don't mind having a bulletin so much as the claim that it's fixed in 1.98.9 or newer, when that release doesn't appear to exist yet. Feels pretty weird practice to advise upgrading to a non-existent version.

1.98.9 has already been tagged since bulletin was published (don't know why they chose on github to tag but not release).

1.98.9 version exists! That's not the question. It should already have been made available for Linux distros assuming this resource from Tailscale is accurate https://pkgs.tailscale.com/stable/?v=1.98.9

Edit: Their changelog also mentions the version: https://tailscale.com/changelog#all


Ah, OK, its the weird GitHub non-release that threw me. Thank you!

so you can disable or mitigate it…




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: