Looking at the code, it seems they're reviewing it for more security flaws.
All of these are already covered by patches I've pushed against 2.1.7, except for stuff related to the new forced update feature (introduced in 2.1.8). I already had 2.1.8 working here before I saw this message. I think I'll wait a few more days, just in case they release again by then... Cheers, Avi.
signature.asc
Description: OpenPGP digital signature