Linux Distro Model Video about old Packages

You are correct the Linux open source community allows you to do whatever you want but does not mean you should do that. The issue however becomes the user ultimately pays the price with bugs or potential security vulnerabilities which in my opinion is not okay to do even though you are allowed to do that with the open source licensing. This to me seems like a problem with Linux not wanting to make changes since this is how we always did things instead of making changes that would ultimately improve the Linux experience for both the end user and app developers.

Oh, they do. The Kernel is one Example. And they have a Backports Repo. I can name as an Example ClamAV. They switched to a newer Version.

They do Bugfixes, too if I remember correctly from Changelog's.

I do not use Gnome desktop. Part of the issue is, that Gnome is rather pervasive.
They control GTK, and in having that, broke it into two parts: GTK (the toolkit) and LibAdwaita (The lock and control for the toolkit).
"Well. just don't use it" is not actually functional advice.

This statement does not make a lot of sense to me.
1.) Are there actual security vulnerabilities that users need to be sitting on the edge of their seat about? Everyone loves to talk about vulnerabilities and security, but no one talks about the fact that actual exploitative actions are exceptionally rare, or that LTS using people are among the safest and secure software users.
2.) Why are you saying LTS editions are out of date and unmaintained. They 100% are maintained.
Yes, stable versions do tend to lock in the package version. This is nothing new. But the vast majority get security updates and the slim minority that don't are primarily because they have no security vector.

Neither Ubuntu nor Debian uses stock or Vanilla Gnome. They customize it pretty heavily.
But the next statement is... Backwards.
It is Gnome that brought LibAdwaita into the mix in order to force users to adhere to its HIG.
Mint does everything it can to mitigate that forced usage and restore freedom to the Owner of the Computer.

It absolutely does do backports.

What is the price of Freedom? :neutral_face:

Debian uses actually Vanilla Gnome. Ubuntu does not.

It is functional advice if GNOME is going in a direction you disagree with you stop using it and move on to another desktop environment and applications.

[quote="Aravisian, post:23, topic:66666"]

  1. It does make sense since users are dealing with bug that have been patched by the app developer multiple versions ago since Linux distributions are not back porting these fixes hence GNOME having an issue. It does not matter how rare they currently are for Linux now since that will change the more the user base grows since that will get the interest of hackers to exploit.
  2. That is partially true the Linux kernel/operating system is up to date but not the prepackaged apps that are obsolete that are multiple versions behind the currently supported version the app developer offers. Keep in mind fixes are not being back ported by the distribution hence GNOME complaining.

What are you talking about? Debian uses vanilla GNOME. In addition both Ubuntu and Zorin OS use GNOME extensions to alter the appearance which I believe is still officially supported by GNOME to alter it's appearance. Quite frankly I disagree Mint is doing everything it can to put their users security at potential risk and shipping GNOME applications that are broken without back porting the fixes that were released in later versions by GNOME.

I would prefer my personal data not being on the dark web hence why it is important to ship bundled software that is supported by the app developer.

Then why is GNOME complaining if the back ports of fixes are being implemented?????? I think the answer is obvious to the question the back ports are not happening hence GNOME getting bug reports for issues that have been previously fixed versions ago.

I think you bypassed the crux of the issue there.

It absolutely one hundred percent, unequivocally does matter.
Ephemeral ghosts of a haunting threat is not evidence of a real threat vector. This is just fear gimmick, not valid security.

It is fully true. You stating those packages are outdated and obsolete does not make them so - and I can give you a very simple exercise in logic as to why:
They are stable versions because they worked during their entire release. Before the New and Shiny version was released; these Were the New Shiny Fixed versions. They worked.
On rare occasion, a bug does persist past initial bug evaluation. More often, they are discovered much later. Again, this is uncommon.
Using Fear as a debate tactic runs into the problem of when it must support its claims against observational evidence.

Debian uses Upstream Gnome.
Except; packages are split and integrated into Debian's package management.
Debian rechooses default applications rather than Gnome's set guidelines.
Debian applies bug fixes and security patches to them, in house
Upstream defaults are adjusted and extensions are used.

This is a statement of assumed fear, not evidence based.
Are LTS packages leaking your data to the Dark Web? Do you have evidence to support this? Is there Any Evidence At All, that LTS packages are compromised in this way?

Actually... the more common thing is that Gnome refuses to fix bug reports on older packages, period. It's a wontfix under the claim it is no longer supported. This is Well Documented.
And it is why Gnome Bugs - these are bugs in Gnome packages, introduced by Gnome... are well documented to persist for many years.
It is called "Shifting the goal posts" or "passing the buck."

No I have not if you do not like the direction of the GNOME project leave. It is as simple as that. Linux has multiple other apps and desktop environments you can use.

Here is a You Tuber talking about some of the decade old bugs in the Linux kernel that are being found with AI tool kits that are in the process of being patched. I wonder if those AI tool kits would find bugs in these bundled obsolete software bundles that are no longer updated by the developer.

It is not fully true since GNOME is complaing about the Linux distributions shipping very old obsolete apps they are receiving bug reports for issues that have long been fixed in the supported versions of the application.
You said in a previous post the Ubuntu and Debian modify GNOME. That is simply false for Debian since they ship stock GNOME. Ubuntu does modify GNOME via GNOME extensions which are still supported by the way.

It is called common sense not to use obsolete software since any vulnerabilities are never going to be patched. They are technically supposed to be back ported with Linux but that obviously is not happening if GNOME is complaining about it. Same reason why I am not actively using Windows XP or Windows 7 on the internet.

It is not passing the buck if Linux distributions are shipping older unsupported GNOME apps with issues that have long been resolved in the supported versions.

And use... what?
Remember that bit about "pervasive?" That they control GTK?
It is Not So simple.

Here is the thing: The current standard - on Mac, Windows OS and has been all along on GnuLinux, is to fix bugs in standard packages, not isolate those fixes to only the latest as Gnome is wont to do - and there, you see who the odd one out is.

No.

Present the evidence.

It is NOT common sense that your data is on the Dark Web due to Ubuntu Apps.
The onus is on you to support that claim With Evidence.
You keep pointing to Supposed Risks, Claimed Threats. Show them.

If they are real, you should have no problem.

7 posts were split to a new topic: Cleanup of Existing thread

It is primary like already mentioned in the Video: There come Issue Reports for outdated Program Versions. Yes, Stuff can be fixed through Backporting. And that happens. but how good it happens is a bit difficult.

And here is then the Reporting an important Point: When You have an Issue but You report it to Gnome, it isn't the right Target. It should be reported to the responsible Distro. But: These Links directly in the Program are not changed. So, as a User, You see this and think that this is the right Thing to do when using it. But it isn't.

Like I already wrote above:

1 Like

im not sure where all this "LTS distros dont fix bugs of applications" comes from. they do, they just cant fix every bug of every application, even less if it's a small or rare bug that goes unnoticed by most

i use debian stable, and occassionally, i see stable applications get updated with a subname "+deb{debian release number}u{number of bugfix updates made by debian}"

this does also manifest in everyday use too; in debian 12, there was a bug that crashed the plasma shell. I dont remember right now how to trigger it (i think it was cancelling a copy-paste operation), but it was reproducible, as in, i could follow those exact steps and it would crash. One day, after an update, i accidentally did that without realizing it would crash until i had already done that, but it didnt crash. I tried multiple times and couldnt get the plasma shell to crash a single time. The bug had been fixed even though kde was no longer maintaining that version

obviously, a distro that maintains thousands of packages (or a few dozens or hundreds, in the case of forked distros like mint) and has to focus on many areas at once (like, in the case of mint, the new system administration app or the wayland session, as well as fixing bugs on their own software like the cinnamon desktop). Obviously, they cant apply bugfixes for applications at the same speed as a team thats dedicated entirely to that application. Nor does it mean that every bug is important enough for it to be a problem. And if, as an example (i dont remember the exact numbers said in the video but the point stands), they say 134 bugs were fixed between versions 43 and 49... what metric is being used there? is it since the first release of 43 or the final one? how many of those bugs didnt exist in version 43 and were added in the newer versions? and how many of those bugs would cause a risk for the user instead of a slight annoyance that, depending on the specifics of the bug, they might not even encounter? It seems quite ambiguous

and most importantly: there is choice. The same user that chose a LTS distro is free to move to a rolling release distro like arch, or a point release distro like fedora or non-LTS ubuntu, or even debian testing. Inside the LTS distros, they can enable backports. In the case of mint (as it's the one mentioned in the video, but this would also include zorin) flatpak support is enabled ootb for those who want a stable base combined with a newer veesion of a program. Just because LTS distros exist doesnt mean you are forced to use them if you dont like how they work

only point i agree with in the video is that the bug reporting button should link to the distro's issue tracker instead of the program's

2 Likes