This new pages accomplishes several interrelated things: * Documents that Zulip Cloud runs master and how that works. * Documents policies on how long client apps are expected to support old releases in our compatibility matrix. * Removes the 3-years-stale roadmap article. * Provides a central place to talk about different versions in Zulip. * Provides a better place to link to from our "you need to upgrade" nag. This content is not intended to be final, but should be finalized in the next week or so. Fixes #18322.
1.2 KiB
Security policy
Security announcements are sent to zulip-announce@googlegroups.com, so you should subscribe if you are running Zulip in production.
Reporting a vulnerability
We love responsible reports of (potential) security issues in Zulip, whether in the latest release or our development branch.
Our security contact is security@zulip.com. Reporters should expect a response within 24 hours.
Please include details on the issue and how you'd like to be credited in our release notes when we publish the fix.
Our security model document may be a helpful resource.
Supported versions
Zulip provides security support for the latest major release, in the form of minor security/maintenance releases.
We work hard to make upgrades reliable, so that there's no reason to run older major releases.
See also our documentation on the [Zulip release lifecycle][release-lifecycle]