aio-libs / aio-libs/aiohttp

Publish release lifecycle, support duration and security reports

未关闭
#2,853 17 条评论 1 个 reaction 已指派 0 人 在 GitHub 查看
enhancement meta
主要语言
Python
星标
16.5k
派生
2.4k
平均合并
20 小时 10 分钟
30 天内合并 PR
221

描述

I'm about to start a new project (an open source event/ticketing platform) I obviously want to use aiohttp but I have a few questions/requests about long term support and security.

It's particularly relevant in this project as I hope the platform will run for the client for years without significant maintenance from me or any sysadmin.

Could aiohttp publish a life-cycle for major releases: eg. how long they will be fully supported for, how long critical security issues will be fixed for?

Also, as per #2751 it would be good if aiohttp had an official procedure for reporting security issues and stated how we will deal with them.

I guess in summary I'm asking for a simplified version of https://docs.djangoproject.com/en/2.0/internals/security/. Is this possible?

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。