aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorDominik Picheta <dominikpicheta@googlemail.com>2018-07-08 21:07:22 +0100
committerGitHub <noreply@github.com>2018-07-08 21:07:22 +0100
commit2adc09836cc3527546f464dcf42a7f3fc067b28d (patch)
treed75c846a284ae047c6eaeb7f278e8500ecaf4c5b
parentd75de5470391038136631a4d621ce84c9f8846ad (diff)
parentc4f2a21f0368d44df370605d40d64c6244af9aa9 (diff)
downloadpackages-2adc09836cc3527546f464dcf42a7f3fc067b28d.tar.gz
packages-2adc09836cc3527546f464dcf42a7f3fc067b28d.zip
Merge pull request #789 from nim-lang/FedericoCeratto-patch-3
Add vulnerability management, bump SemVer version
-rw-r--r--README.md3
1 files changed, 2 insertions, 1 deletions
diff --git a/README.md b/README.md
index a32bdea..d889e63 100644
--- a/README.md
+++ b/README.md
@@ -37,6 +37,7 @@ While we really appreciate your contribution, please follow the requirements: ot
* The package should build correctly with the latest Nim release
* The package should not contain files without a license or in breach of 3rd parties licensing
* Non-mature packages should be flagged as such, especially if they perform security-critical tasks (e.g. encryption)
+* If a vulnerability is found, make a patch release against the latest stable release (or more) that fixes the issue without introducing any other change.
* Tiny libraries should be avoided where possible
* Avoid having many dependencies. Use "when defined(...)" to enable optional features.
* If abandoning a package, please tag it as "abandoned"
@@ -44,7 +45,7 @@ While we really appreciate your contribution, please follow the requirements: ot
* Provide a contact email address.
* Optionally try to support older Nim releases (6 months to 1 year)
* Optionally GPG-sign your releases
-* Optionally follow [SemVer](http://semver.org)
+* Optionally follow [SemVer 2](http://semver.org)
Your packages may be removed if the url stops working. It goes without saying
that your pull request will not be accepted unless you fill out all of the