Reply to post: Re: Or backport the fix

Four million outdated Log4j downloads were served from Apache Maven Central alone despite vuln publicity blitz

b0llchit Silver badge

Re: Or backport the fix

You can patch the older version, but it has the same problem/advantage as poisoning the package. The hash of that specific version changes. That should let some build systems fail if they have previously seen that package. IMO, if it is (mostly) the same behavior in the build, then you should pull the old package and force a fix of the build scripts.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon