Advance Notice For Critical Security Releases - Question | JoomShaper

Advance Notice For Critical Security Releases

Mo Ahmed

Mo Ahmed

General 2 days ago

Hi team,

Could you please give us some advance notice when a critical security release is coming—for example:

“We’ll be releasing a critical security update on [date] at [time].”

You wouldn’t need to disclose the vulnerability before the patch is available. The notice would simply give agencies and site owners time to prepare.

Releasing a critical update without warning means I have to drop everything and start patching websites immediately. These updates need to be tested carefully because they can - and sometimes do - break the sites I manage that uses them. With some notice, I could block out the time, rearrange meetings in advance and let clients know what’s happening.

Once a patch is public, malicious actors can compare the old and new files to work out what changed and potentially develop an exploit. That makes it important for us to deploy the update quickly, but it’s much harder to do that safely when the release comes without warning. It gives me less time to also debug the sites when the site fails.

I appreciate that there will be occasions when a patch genuinely needs to be released immediately. However, when circumstances allow, even a short advance notice would help us plan properly and update affected sites more quickly and safely.

Thanks.

2
5 Answers
Rashida Rahman
Rashida Rahman
Accepted Answer
Support Agent 2 days ago #232620

Hi there,

Thank you for taking the time to share this detailed feedback.

We completely understand your concern and appreciate the challenges that agencies and site owners face when a critical security update requires immediate attention across multiple websites.

Your suggestion of providing a short advance notice, without disclosing any vulnerability details, is certainly reasonable. It would give users some time to prepare, schedule maintenance, and test the update while still allowing the actual security details to remain undisclosed until the fix is available.

We'll forward your feedback to our team for consideration. We understand that advance notice may not always be possible, particularly when an issue requires an immediate release, but we'll certainly keep your suggestion in mind for situations where prior notification is feasible.

Thanks again for the constructive feedback and for helping us understand the practical impact of these releases on your workflow.

Best regards,

0
Rashida Rahman
Rashida Rahman
Accepted Answer
Support Agent 2 days ago #232697

Thanks for accepting the answer:)

Have a nice day!

0
Toufiq
Toufiq
Accepted Answer
Senior Staff 2 days ago #232625

Hi there,

Thank you for reaching out. I completely agree with this request. I will discuss it with our developer team and get their confirmation on whether we can provide advance notice for critical security releases whenever circumstances allow.

Once our developer team agrees, I will notify everyone through a newsletter so that you have sufficient time to prepare, test, and deploy the updates safely.

Best regards,

Toufiqur Rahman (Team Lead, Support)

0
PH
Pascal - HTProtect.org
Accepted Answer
2 days ago #232658

I have just updated HTProtect to 2.7.1 (Changelog).

It handles JoomShaper (and other Joomla extension) vulnerabilities largely automatically - auto-updating where possible, plus a secure, reversible auto-patching mechanism for Joomla 3 that installs JoomShaper's own official J3 security patches (Helix Ultimate and Helix3). Where no automatic fix exists, it warns and blocks common attacks via its firewall where feasible.

And just to put the recent JoomShaper issues into perspective: security vulnerabilities are obviously not a JoomShaper-specific thing. Quite a few well-established Joomla extensions have had multiple vulnerabilities disclosed recently, too.

HTProtect aims to be an all-in-one Joomla security solution; its security features are free. It tracks the Joomla vulnerabilities from the NVD feed - you can see the coverage transparently here: https://htprotect.org/en/joomla-vel-feed

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 2 days ago #232660

@Pascal your team makes so many updates, wow, impresed.

I hope we will find time to talk on JoomlaDay soon.

1