pull down to refresh

I was a little bit too harsh on CLN.
I reacted in emotion when I should have analyzed the situation first. I am sorry.
They are in a tough place apparently, on how to publish an update without disclosing the vuln to those who might exploit people who are not patched yet. My respects goes out to the CLN dev team and their work.
However, I still stand by my concerns over closed source updates, and I would advise to not trust anything closed source. If CLN releases the security update as open source eventually, as it seems like the plan is, then that is good. If it were me, I personally would just be running CLN in offline mode instead of trusting a closed source update, then to wait for the open source security patch. But, at least people have choices here.