Skip to content

docs: state the support horizon and what happens if maintenance stops - #11

Merged
CaffeinatedCoder merged 1 commit into
test/security-policy-consistencyfrom
docs/support-horizon
Aug 16, 2026
Merged

CaffeinatedCoder merged 1 commit into
test/security-policy-consistencyfrom
docs/support-horizon

Conversation

@CaffeinatedCoder

Copy link
Copy Markdown
Owner

Stacked on #6 (extends SecurityPolicyConventionTests); retargets to main once that merges. Mirror of EFCore.ComplexIndexes#22.

Why

SECURITY.md said which line receives fixes and that older majors are dropped — but not for how long the current line lives, or how its end would be signalled. Those are the two things a downstream consumer doing CRA-era supplier due diligence asks right after "do you have a disclosure channel".

What

Three short paragraphs under Supported versions:

  • For how long — tied to what the packages target: .NET 10 (net10.0; EF Core 10 for the EF packages), maintained while Microsoft supports that .NET release (LTS, November 2028) or until a new major supersedes it. With the honest note that majors here are cheap and a new one has never meant the old one lost fixes before its successor shipped. No fixed date, no SLA — an intention, phrased as one.
  • If this project stops being maintained — the single-maintainer risk named plainly; what "unmaintained" would look like (archived repo, deprecated packages, note in the policy); published versions stay on nuget.org; MIT; forking is the intended continuity mechanism.
  • How advisories reach consumers' tooling: GHSA → GitHub Advisory Database → NuGetAudit on dotnet restore.

The .NET major in the horizon sentence is anchored to the core project's TargetFramework by a new SecurityPolicyConventionTests method — moving to net11.0 without moving the sentence fails the build.

Verified (verify-the-guard)

Passes as written; fails with the sentence saying .NET 11; fails with the anchor phrase reworded; passes restored.

Wording is yours to adjust — the test only pins the number.

🤖 Generated with Claude Code

SECURITY.md said which line receives fixes and that older majors are
dropped, but not for how long the current line lives or how its end would
be signalled — the two things a downstream consumer doing CRA-era supplier
due diligence asks for after "do you have a disclosure channel".

The horizon is tied to what the packages target: .NET 10 (and EF Core 10
for the EF Core packages), maintained while Microsoft supports that .NET
release (LTS, November 2028) or until a new major supersedes it — with the
note that majors here are cheap and a new one has never meant the old one
lost fixes before its successor shipped. No fixed date, no SLA — an
intention, phrased as one, with the promise that a change is recorded
there first. A second paragraph names the single-maintainer risk plainly,
says what "unmaintained" would look like, and that forking is the intended
continuity mechanism. A third says how advisories reach consumers'
tooling: GitHub Security Advisories → GitHub Advisory Database → NuGetAudit
on restore.

The .NET major in the horizon sentence is anchored to the core project's
TargetFramework by SecurityPolicyConventionTests, so moving to net11.0
without moving the sentence fails the build.

Verified: the new test passes as written, fails with the sentence saying
.NET 11, fails with the anchor phrase reworded, passes restored.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@CaffeinatedCoder

Copy link
Copy Markdown
Owner Author

Dispatched run for this branch (base isn't main): https://github.com/CaffeinatedCoder/CodoMetis.ValueRanges/actions/runs/31946137420 — green. After #6 merges, Update branch to get the checks here.

@CaffeinatedCoder
CaffeinatedCoder merged commit 9c97af1 into test/security-policy-consistency Aug 16, 2026
3 checks passed
CaffeinatedCoder added a commit that referenced this pull request Aug 16, 2026
docs: land the support horizon on main (recovers #11)
@CaffeinatedCoder
CaffeinatedCoder deleted the docs/support-horizon branch August 16, 2026 17:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant