My hosting provider was going to upgrade every phpBB forum installed through its control panel.
The target was phpBB 2.0.20. The window was May 15 through May 17. Earlier versions had new security problems and the provider was not waiting around for every customer to patch by hand.
There was an opt-out. Put an empty file named donotupgrade in the forum directory and the automated job would skip it.
That did not make the security problem disappear. It moved the responsibility to me. If an old forum was used to compromise the server, the host could disable the site.
The automatic path had its own risk. Modified themes and scripts might be overwritten. Before the window opened, I had to find the installation, check the custom work, make a backup, and decide who was applying the patch.
The notice named a domain in my account. I am leaving it private because the email does not establish who owned the project or whether it should still be tied to me.
It also does not record what I chose. There is no reply saying I accepted the managed upgrade, created the opt-out file, or patched it separately. There is no compromise report.
The part that survived is the choice:
- let the host install 2.0.20 and protect the custom work first;
- stop the host and own the upgrade myself.
Ignoring it was not one of the options.
The provider gave me one week to check the installation and pick a side. That was enough time if I started before the upgrade window, not after it.