Hi team,
Could you please give us some advance notice when a critical security release is coming—for example:
“We’ll be releasing a critical security update on [date] at [time].”
You wouldn’t need to disclose the vulnerability before the patch is available. The notice would simply give agencies and site owners time to prepare.
Releasing a critical update without warning means I have to drop everything and start patching websites immediately. These updates need to be tested carefully because they can - and sometimes do - break the sites I manage that uses them. With some notice, I could block out the time, rearrange meetings in advance and let clients know what’s happening.
Once a patch is public, malicious actors can compare the old and new files to work out what changed and potentially develop an exploit. That makes it important for us to deploy the update quickly, but it’s much harder to do that safely when the release comes without warning. It gives me less time to also debug the sites when the site fails.
I appreciate that there will be occasions when a patch genuinely needs to be released immediately. However, when circumstances allow, even a short advance notice would help us plan properly and update affected sites more quickly and safely.
Thanks.