Read the releases the security policy said did not exist - #366
Merged
Merged
Conversation
`SECURITY.md`'s supported-versions section told a reporter there is no released version and pasted both of its commands as producing nothing. Two releases exist, 0.1.0.0-stable on 2026-09-03 and 0.1.1.0-stable on 2026-09-04, and both commands produce output, so every sentence in the section rested on an absence the tracker contradicts. The failure this prevents is the one that matters most in this file: the plugin is installable from a public catalogue, and a reporter holding a finding against a released archive opens this section to see whether it is in scope and is told the version they are holding does not exist. The most likely next act is that they do not report it. The section now names both releases with the commands that read them and says a fix lands on the default branch. The support window is the half to read carefully: it stays absent, and the change is that its absence is now a decision nobody has taken rather than something entailed by there being no version. No window is offered, none is implied, and the section says it will name the supported versions on the day that is decided. The correction is marked in the text rather than made silently, in the shape this repository already uses, so a reader who saw the old sentence can see that it moved. No leg is added and none is claimed. The suite runs with no network, so nothing here re-derives a release listing, which is how the old sentence survived two releases; that is now written in the section instead of being left to be assumed. Signed-off-by: Nils Lehnen <30603423+iderex@users.noreply.github.com>
iderex
deleted the
docs/the-security-policy-said-nothing-was-released
branch
September 5, 2026 08:07
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs #365
Finishes: #365
What was wrong
Both commands produce output:
So every sentence in that section rested on an absence the tracker contradicts,
in the file a person reports a vulnerability from, in the section they read to
find out whether what they are holding is in scope. The plugin is installable
from the catalogue at the address the readme gives, so a reporter with a finding
against a released archive was told the version they hold does not exist. The
most likely next act is that they do not report it.
What it says now
Both releases, with the commands that read them, and a fix landing on the
default branch.
The support window is the half to read carefully, and it is the half this change
is most careful about. It stays absent. What changes is that its absence is a
decision nobody has taken rather than something entailed by there being no
version, and the section says so in those words: no window is offered, none is
implied, nothing says a fix will be carried back to a released version and
nothing says it will not, and the section will name the supported versions on
the day that is decided. The negative disclosure stays negative and does not
become an assurance in either direction.
The correction is marked in the text rather than made silently, in the shape this
repository already uses, so a reader who saw the old sentence can see that it
moved.
What holds it, which is nothing, and why that is stated in the section
No leg is added and none is claimed. The suite runs with no network, so nothing
here re-derives a release listing; that is exactly how the sentence being
replaced survived two releases without reddening anything, and the section now
says it rather than leaving a reader to assume the block is checked.
The fenced list
SecurityPolicyTestsreads is at the top of this file and isuntouched.
per target, over both server lines, before the change and after it.
What this does not decide
Which versions get a support window. That is a decision and this change does not
take it, which #365 says in its own body.
Reading
No second reader looked at this. The commands above are the evidence in place of
one.