Menu

#111 Downloads site gives misleading information about Windows downloads

v1.0 (example)
open
nobody
None
5
2019-06-13
2019-06-13
trimeta
No

In light of the recent modeline security issue (CVE-2019-12735), many users are going to want to update their version of Vim to the latest secure version. However, the portion of the Downloading Vim site (https://www.vim.org/download.php) discussing Windows downloads is misleading and out of date. The 8.1 builds were uploaded on 2018-05-18, and the Cream builds (which are described as being "the latest version with all patches included") are from 2011-01-24 and 2018-03-19, depending on whether you get the version with or without the Cream patches. The only updated versions are the nightlies available through the vim-win32-installer GitHub (https://github.com/vim/vim-win32-installer/releases) and Yongwei's build (http://wyw.dcweb.cn/index.htm#download).

The portion of the page discussing Windows installation options should be rewritten to clarify that the nightlies are the only way to get recent, updated versions of Vim for Windows. The other options included in the archives (https://ftp.nluug.nl/pub/vim/pc/ and ftp://ftp.vim.org/pub/vim/pc/) may be discussed in terms of downloading old versions or unusual installation use cases, but it should be made clear that GitHub is the preferred location to download from.

Normally I would call this sort of gripe a feature request, not a bug, but due to the security implications of recommending outdated, insecure versions, I feel it rises to the level of bug.

Discussion


Log in to post a comment.

MongoDB Logo MongoDB