G
Graphite
ANALYTICS
Velocity0.0
Scalable real-time metrics graphing and storage system
Graphite's answer to its own CVE backlog is a pre-release nobody calls official.
time-seriesmetricscve-backlogstalled-releasesunofficial-builds
◆Current state
Graphite's release feed shows three entries across four years. The last tagged work is a pair of 1.2.1 pre-releases whose own notes decline to call them official: they exist, in the maintainer's words, as a master-branch milestone for people who want to avoid CVE checks against 1.1.x, with the second adding XSS fixes. Both point at a single open discussion thread about the state of the project.
◆Where it's heading
This is a project whose maintenance and its release process have come apart. The security fixes are real and are in master, but nothing has been promoted to a release users can adopt through normal channels, which leaves operators choosing between a version that fails CVE scans and an explicitly unofficial tag. The four-year gap since the 1.1.9 preparation commit is the clearest signal available.
◆Prediction
Nothing in these entries supports a confident call on a 1.2.1 final; the maintainer has pointed the question at a discussion thread rather than a roadmap.
◆Recent moves
- 4mo ago
Unofficial master milestone adding XSS fixes
The second pre-release, adding XSS fixes to the CVE-avoidance rationale of the first. Its own note declines to call it official, which leaves the security content stranded outside a supported release.
View source ↗ - 11mo ago
Unofficial master milestone for avoiding 1.1.x CVE checks
A tag cut specifically so operators failing CVE scans against 1.1.x have something to point at. It is described as a milestone rather than a release and directs users to a discussion thread on the project's state.
View source ↗ - 4y ago
Merge commit preparing the 1.1.9 release
A conflict-resolution merge preparing 1.1.9, and the last entry before a three-year gap. Its presence in a release feed is an artefact of how the project tags.
View source ↗