What you gain in "PCI compliance" you may lose in server stability. I doubt there is anything critically different between those PHP releases. Mixing repos (fc7 and fc10) can get messy and I've been burned in the past by doing this. I would either stick with what you have, upgrade the whole box to fc10, look for a backport package for fc7, or compile your own. Or what I would really actually do is just stay put with the old version of PHP and tell management to thumb it.
|