WetGeek thank you for confirming this. like you, I have to assume this meant nothing.

cherry-picked discord 0.0.70

Harvey i just synced this cherry pick and saw that my bash got updated to 5.2.32, release 83.

Is the bash update correct?
I'm asking because bash was not specified in your list of cherry-picks.

Thank you.

    All went fine for me on Plasma and im getting used to discover.
    I like it, don
    t care much about the size of the updates.

    Harvey got the updates for FF and Bash and rebooted. thanks!

      brent got the updates for FF and Bash and rebooted

      Did you check the version numbers after your "updates"? In order to get the update for Vivaldi, I needed to use --reinstall when I updated. Else, I just got a message telling me that it was already installed, and wouldn't be installed again. Apparently not all of the numbers in the version are significant to eopkg.

        WetGeek i did read harvey's FF hyperlink before I installed but did not note the FF version number when I did install. There was no incident with the cherry-picked packages.
        We both recently got "Re-install same version of package? (yes/no)" and you just got "it was already installed, and wouldn't be installed again" so a little redundancy/overlap with all the moving parts lately is my theory(?).

        edit:

        WetGeek I needed to use --reinstall when I updated. Else, I just got a message telling me that it was already installed
        not the expected behavior for sure

        snowee

        If updates are available they are always correct, just because something is not listed as being cherry-picked does not mean it is a mistake. I did not mention it because I did not cherry-pick it, someone else on the team did it well before my cherry-picks. The bash update fixes an issue that is only relevant when we create a new ISO so they probably didn't feel it warranted mentioning it here.

          Harvey I had the same question, that answer it.
          Side note: I think it could be, for transparency with the user, better to mention any cherry-pic, in the (hopefully not) possible supply-chain attack scenario would be a bit more obvious to pinpoint. I could be overthinking this though.

            nolan I announce cherry-picks that I do as a courtesy. It will never be mandatory and if it was I would resign. A forum post is not a security feature.

            FTR, just because we have made a habit of putting out nice summaries of changes, alongside sometimes announcing cherrypicked packages, it doesn't mean that our lovely users should expect everything to get announced; we highlight stuff that looks interesting and the rest we leave out at our discretion.

            As it happens, I was the person who approved the bash PR (which dealt with reinstating missing install-time defaults), and who subsequently asked if the bash package could be cherrypicked to shannon.

            We build Release Candidate ISOs from the shannon repo, so it needed to go in for RC ISO testing. These kinds of changes can happen during RC freeze periods.

            End of story.

              As far as i know this is the only distro that on a regular basis announces description about software updates. Other distros like Linux Mint only announces anything regarding updates when they shift from ver. 22 to 22.1 and so on, which only occur about every 6 months. So i consider Solus users to be very lucky that the team are so transparent about this and it brings confidence in the distro. Lets not push it and demand more because i think they do a lot more than expected already. And i would also like to thank all the good people that work together and make this great distro 🙂

                nolan in the (hopefully not) possible supply-chain attack scenario would be a bit more obvious to pinpoint.

                In that case the hypothetical attacker could just include his update as part of the weekly sync then

                  Not just a bonus but essential for critical (security) issues that don't allow a week's wait. And that's exactly why I'm grateful that it works like this at Solus.
                  curated weekly rolling and critical cherry picks in between.
                  exactly my thing. Super cool....

                  will the current update checker survive when the software center dies? i dont like the way discover handles this, and i dont like the gnome one either
                  happy to do everything else in terminal though