You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Following up on issue #286, I’ve been thinking about the current security expectations for projects in the Emeritus category (especially now that they technically fall under our CNA).
Some of these projects are archived or frozen, while others still apply patches occasionally (e.g., requirejs/requirejs@945ae6b).
To open the discussion:
Are Emeritus projects expected to continue managing CVEs (e.g., creation, dispute, triage)?
Are they expected to produce and release security patches?