Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update security policy regarding backporting patches #1961

Merged
merged 2 commits into from
Jan 26, 2025

Conversation

cary-ilm
Copy link
Member

This wording captures our policy: we commit to fixes for main and the most recent minor release, but prior to that, discussed on a case-by-case basis. Better to leave it at than than attempt to be more specific, since those specifics can be determined based on the situation.

SECURITY.md Outdated
| 3.0.x | :warning: Only the most critical fixes, only if they can be easily backported. |
| 2.5.x | :warning: Only the most critical fixes, only if they can be easily backported. |
| <= 1.x | :x: No longer receiving patches of any kind. |
| main | :white_check_mark: :construction: All fixes immediately, although this branch is under development with potential unstabe ABI/API
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
| main | :white_check_mark: :construction: All fixes immediately, although this branch is under development with potential unstabe ABI/API
| main | :white_check_mark: :construction: All fixes immediately, although this branch is under development with potential unstable ABI/API

SECURITY.md Outdated
Comment on lines 74 to 75
| 2.5.x | :warning: Patch releases considered in response to specific requests
| <= 1.x | :x: No longer receiving patches of any kind |
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What about 2.0-2.4?

This wording captures our policy: we commit to fixes for main and the
most recent minor release, but prior to that, discussed on a
case-by-case basis. Better to leave it at than than attempt to be more
specific, since those specifics can be determined based on the situation.

Signed-off-by: Cary Phillips <[email protected]>
2.4 was the first release by the ASWF, recent enough to negotiate
patches. Prior to that our knowledge is so limited, and CMake support
was so fragile, that we should not even entertain the possibility.

Signed-off-by: Cary Phillips <[email protected]>
@cary-ilm cary-ilm merged commit 3ce6c2b into AcademySoftwareFoundation:main Jan 26, 2025
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants