My understanding (correct me if I'm wrong) is that when a vulnerability is fixed in the LTS queue a new release for the given module can only be created with the maintainer's blessing. What happens if there's no new release? I suppose you can apply the patch manually. But then the mydropwizard module doesn't know about your patch. So you'll need to use something like https://www.drupal.org/project/update_advanced to override the report (if that even works with MDW). But what then if there's a subsequent vulnerability found and fixed for that module? You'd be none the wiser (unless you closely monitor the d6lts queue).
Similarly with Drupal core. Since we know that there will be no more commits to the D6 branch, you will only get accurate reports from MDW if you are running Pressflow (and I'm a bit unclear about whether or not the LTS Vendors are in fact updating Pressflow). If you are running vanilla Drupal, then the MDW module is not useful after the first vulnerability is fixed in core.
Again, this might just be me misunderstanding how things work.
Comments
Comment #2
dsnopekWe make our own special releases (on Github, not Drupal.org) for the LTS patches which get included in our data. We just created one today for Features!
If you look on Drupal.org, there is no Features 6.x-1.3, but if you use this module there is. :-) It gets reported on the "Available updates" report, and can be downloaded via drush.
So far, the LTS vendors haven't made any core patches, but when we do, they will get put into Pressflow and this module will start telling you to update to Pressflow.
Does that answer your questions?