aio-libs / aio-libs/aiohttp

Publish release lifecycle, support duration and security reports

Open
#2,853 17 comments 1 reaction 0 assignees View on GitHub
enhancement meta
Dominant language
Python
Stars
16.5k
Forks
2.4k
Avg merge
20h 10m
Merged PRs (30d)
221

Description

I'm about to start a new project (an open source event/ticketing platform) I obviously want to use aiohttp but I have a few questions/requests about long term support and security.

It's particularly relevant in this project as I hope the platform will run for the client for years without significant maintenance from me or any sysadmin.

Could aiohttp publish a life-cycle for major releases: eg. how long they will be fully supported for, how long critical security issues will be fixed for?

Also, as per #2751 it would be good if aiohttp had an official procedure for reporting security issues and stated how we will deal with them.

I guess in summary I'm asking for a simplified version of https://docs.djangoproject.com/en/2.0/internals/security/. Is this possible?

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.