← Back to all sparks
G

Graphite

ANALYTICS
Velocity0.0

Scalable real-time metrics graphing and storage system

Graphite's answer to its own CVE backlog is a pre-release nobody calls official.

time-seriesmetricscve-backlogstalled-releasesunofficial-builds
Current state
Graphite's release feed shows three entries across four years. The last tagged work is a pair of 1.2.1 pre-releases whose own notes decline to call them official: they exist, in the maintainer's words, as a master-branch milestone for people who want to avoid CVE checks against 1.1.x, with the second adding XSS fixes. Both point at a single open discussion thread about the state of the project.
Where it's heading
This is a project whose maintenance and its release process have come apart. The security fixes are real and are in master, but nothing has been promoted to a release users can adopt through normal channels, which leaves operators choosing between a version that fails CVE scans and an explicitly unofficial tag. The four-year gap since the 1.1.9 preparation commit is the clearest signal available.
Prediction
Nothing in these entries supports a confident call on a 1.2.1 final; the maintainer has pointed the question at a discussion thread rather than a roadmap.

Recent moves

  1. 4mo ago

    Unofficial master milestone adding XSS fixes

    The second pre-release, adding XSS fixes to the CVE-avoidance rationale of the first. Its own note declines to call it official, which leaves the security content stranded outside a supported release.

    View source ↗
  2. 11mo ago

    Unofficial master milestone for avoiding 1.1.x CVE checks

    A tag cut specifically so operators failing CVE scans against 1.1.x have something to point at. It is described as a milestone rather than a release and directs users to a discussion thread on the project's state.

    View source ↗
  3. 4y ago

    Merge commit preparing the 1.1.9 release

    A conflict-resolution merge preparing 1.1.9, and the last entry before a three-year gap. Its presence in a release feed is an artefact of how the project tags.

    View source ↗