How about back-porting the input validation solutions to the branches where we don't want to do database migration?
My concern with a note is that I'm not sure what we would advise deployers to do. If we're fairly comfortable recommending the policy change mentioned by Niall in comment #2, a note around that advice seems appropriate.
How about back-porting the input validation solutions to the branches where we don't want to do database migration?
My concern with a note is that I'm not sure what we would advise deployers to do. If we're fairly comfortable recommending the policy change mentioned by Niall in comment #2, a note around that advice seems appropriate.