← Back to all sparks
A

Asterisk

MEETINGS
Velocity0.0

Open-source framework for building voice, video and PBX communications.

Six branches patched inside thirteen minutes — Asterisk's security process is the story here

telephonyvoipsecurity-releaselong-term-supportbackports
Current state
The entire visible window is a single coordinated security publish. Within thirteen minutes on 25 June, the project shipped security releases across every supported line at once: 23.4.1, 22.10.1, 21.12.3 and 20.20.1 on the standard branches, plus certified-22.8-cert3 and certified-20.7-cert11 on the certified track. Each carries roughly twenty commits and points at the same downloads infrastructure.
Where it's heading
What this shows is the cost structure of a telephony platform with long-lived deployments: four standard branches and a separate certified track all have to receive the same fix on the same day. The engineering signal is not new capability but the ability to backport across six lines simultaneously, which is what enterprise PBX operators actually buy into.
Prediction
Expect the next window to be regular branch releases across the same set of lines, with any further advisory triggering the identical simultaneous publish across all supported and certified branches.

Recent moves

  1. 1mo ago

    Asterisk 23.4.1 security release

    The newest standard branch receives the coordinated security fix set, around nineteen commits. It is the head of the six-branch publish that defines this window.

    View source ↗
  2. 1mo ago

    Asterisk 22.10.1 security release

    The same security fixes backported to the 22 line minutes later. Evidence of the parallel branch maintenance this project runs.

    View source ↗
  3. 1mo ago

    Asterisk 21.12.3 security release

    The 21 line's copy of the coordinated fix set, carrying a slightly larger commit count. Older branches need more adaptation for the same patches.

    View source ↗
  4. 1mo ago

    Asterisk 20.20.1 security release

    The oldest standard branch in the publish receives the same advisory fixes. Long-term deployments are kept on the same patch level as the newest line.

    View source ↗
  5. 1mo ago

    Certified Asterisk 22.8-cert3 security release

    The certified track's 22 line gets the same fixes through its separate release process. Certified builds exist for deployments that need a slower, validated stream and still cannot wait on security.

    View source ↗
  6. 1mo ago

    Certified Asterisk 20.7-cert11 security release

    The eleventh certified build on the 20.7 line, closing out the six-branch publish. Its cert number shows how long this line has been carried.

    View source ↗