For package maintainers, it's reasonable to expect security updates are rolled out the same week that a vulnerability is found. If you can't deploy a new version of a package in 6 months, not maintaining the package is also a valid option.
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
replies: