I'd pay to support that - and note it needs someone paid to review the contributions since otherwise that'd be the best channel to exploit.JDunphy wrote: ↑Sat Jun 27, 2026 2:11 pm Could or should Maldua use its platform to provide patches for emergency security issues? Would it be a series of scripts, ansible playbooks in a repository with a pimbra tag that one could fetch and run given the processing delay for FOSS admins to receive security updates? They could come from contributions from the community given we all benefit when Zimbra isn't associated with the next big exploit in the news.
Jim
I would also set the bar a bit higher: not just that Zimbra isn't cause for another big exploit wave, but that there's no longer need for a CISA warning against using Zimbra.
IDK if some people "accept that risk", but generally we'll all be better of by something that improves the average zimbra install's safety.



