-
Notifications
You must be signed in to change notification settings - Fork 3.1k
Open
Labels
state: needs eyesNeeds a maintainer/triager to take a closer lookNeeds a maintainer/triager to take a closer looktype: docsDocumentation relatedDocumentation relatedtype: maintenanceRelated to Development and Maintenance ProcessesRelated to Development and Maintenance Processestype: securityHas potential security implicationsHas potential security implications
Description
What's the problem this feature will solve?
Usually security policies will include guidance on what versions are eligible for security fixes. I believe pip's historical behavior has been to only apply security patches to the latest release of pip (not backporting security fixes). If this isn't correct we can amend this to whatever future behavior the pip maintainers would like to do for security fixes.
Describe the solution you'd like
Update security policy with guidance on supported versions.
Alternative Solutions
N/A
Additional context
Code of Conduct
- I agree to follow the PSF Code of Conduct.
Metadata
Metadata
Assignees
Labels
state: needs eyesNeeds a maintainer/triager to take a closer lookNeeds a maintainer/triager to take a closer looktype: docsDocumentation relatedDocumentation relatedtype: maintenanceRelated to Development and Maintenance ProcessesRelated to Development and Maintenance Processestype: securityHas potential security implicationsHas potential security implications