Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update SECURITY.md and remove support for 2.x version #4683

Merged
merged 5 commits into from
Nov 14, 2023

Conversation

ernestognw
Copy link
Member

With the new 5.x release, we can remove security fixes support for versions like 2.x
Also, adds support for 5.x release and it'll show up in the Security Policy once merged.

PR Checklist

  • Tests
  • Documentation
  • Changeset entry (run npx changeset add)

@changeset-bot
Copy link

changeset-bot bot commented Oct 13, 2023

⚠️ No Changeset found

Latest commit: af7388b

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@ernestognw ernestognw requested a review from Amxx October 13, 2023 20:26
@@ -30,13 +30,14 @@ Only critical severity bug fixes will be backported to past major releases.

| Version | Critical security fixes | Other security fixes |
| ------- | ----------------------- | -------------------- |
| 4.x | :white_check_mark: | :white_check_mark: |
| 5.x | :white_check_mark: | :white_check_mark: |
| 4.9 | :white_check_mark: | :x: |
Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do you agree with this? @Amxx
We probably would like to keep medium severity fixes in 4.9 along with the critical for some time.

SECURITY.md Outdated Show resolved Hide resolved
Co-authored-by: Eric Lau <[email protected]>
@ernestognw ernestognw requested a review from ericglau November 6, 2023 22:25
@ernestognw ernestognw merged commit 4e17c2e into OpenZeppelin:master Nov 14, 2023
13 checks passed
@ernestognw
Copy link
Member Author

The community keeps referencing the security page and we should communicate correctly what are we supporting. I'm merging.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants