As such, starting from today, I will no longer participate in nginx
development as run by F5. Instead, I’m starting an alternative
project, which is going to be run by developers, and not corporate
entities:
Yeh, seems like the CVEs were against an alpha branch.
So, perhaps its a good reminder not to use alpha in production... But I feel it warranted a bug report instead of a "Common Vulnerabilities and Exploits" notice, normally something used to notify potentially production deployed systems of an issue.
That would be like Pepsi issuing a product recall to all retail outlers for a product that has only been tested internally (kinda)