Feature changed by: Sebastian Wagner (sebix) Feature #322299, revision 5 Title: please update lighttpd package to lighttpd 1.4.44 openFATE: Unconfirmed Priority Requester: Important Requested by: Glenn Strauss (gstrauss) Partner organization: openSUSE.org Description: Please update lighttpd package to lighttpd 1.4.44 for OpenSUSE Leap and OpenSUSE Tumbleweed, and maybe also consider for OpenSUSE 13.2 and SUSE SLE-12. lighttpd 1.4.37 is over a year old and is missing a number of security fixes, including protection against HTTPoxy and XSS fixes. lighttpd 1.4.44 builds fine on various OpenSUSE platforms. I am one of the developers of lighttpd, as is stbuehler, who builds (unofficial) packages for opensuse at https://build.opensuse.org/package/show/home:stbuehler:lighttpd-1.4.x/lightt... Future looking, what is the process for getting new lighttpd releases into Tumbleweed? Thank you. Discussion: #1: Marcus Rückert (darix) (2017-03-06 14:09:18) done for Leap and Tumbleweed. we won't update it on SLE as afaik not all changes are backward compatible. + #2: Sebastian Wagner (sebix) (2017-03-12 08:57:45) + Submitted 1.4.45 from Factory to Leap 42.3 as 42.2 still had 1.4.37: + https://build.opensuse.org/request/show/478802 -- openSUSE Feature: https://features.opensuse.org/322299