[mapserver-dev] Feedback on new SECURITY.md policy for MapServer

Jeff McKenna jmckenna at gatewaygeomatics.com
Fri Jul 30 09:19:37 PDT 2021


Hi devs,

GitHub now recommends that all repositories contain a SECURITY.md file (per https://docs.github.com/en/code-security/getting-started/adding-a-security-policy-to-your-repository).  I followed their steps and drafted one for MapServer through this commit: https://github.com/MapServer/MapServer/commit/dab99913d214c5440815f4c9955c49e3e7a0f684

Question:  what versions should we list as supported, for security patches?

>From checking our recent release history, I initially wrote that we support 7.6, 7.4, 7.2, 7.0, but not < 7.

personally, i feel that we should only support the current stable release, and the previous branch, such as:  8.0.x, and 7.6.x    (my reasoning: we are doing this for free/on our own time, and supporting too many past versions is not realistic, as we all have bills to pay).

please share your thoughts.

thanks!

-jeff


--
jeff mckenna
gatewaygeo: developers of ms4w, mapserver consulting and training
co-founder of foss4g
http://gatewaygeo.com/




 7.="" personally,="" i="" feel="" that="" we="" should="" only="" support="" the="" current="" stable="" release,="" and="" the="" previous="" branch,="" such="" as:="" 8.0.x,="" and="" 7.6.x="" (my="" reasoning:="" we="" are="" doing="" this="" for="" free/on="" our="" own="" time,="" and="" supporting="" too="" many="" past="" versions="" is="" not="" realistic,="" as="" we="" all="" have="" bills="" to="" pay).="" please="" share="" your="" thoughts.="" thanks!="" -jeff="" --="" jeff="" mckenna="" gatewaygeo:="" developers="" of="" ms4w,="" mapserver="" consulting="" and="" training="" co-founder="" of="" foss4g="" http://gatewaygeo.com/=""></ 7.

personally, i feel that we should only support the current stable release, and the previous branch, such as:  8.0.x, and 7.6.x    (my reasoning: we are doing this for free/on our own time, and supporting too many past versions is not realistic, as we all have bills to pay).

please share your thoughts.

thanks!

-jeff


--
jeff mckenna
gatewaygeo: developers of ms4w, mapserver consulting and training
co-founder of foss4g
http://gatewaygeo.com/




>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.osgeo.org/pipermail/mapserver-dev/attachments/20210730/ef41b335/attachment.html>


More information about the mapserver-dev mailing list