Skip to content

Conversation

@fulldecent
Copy link
Contributor

The publish Solidity security policy should be helpful to people when deciding which version of Solidity to use. So a reference is added.

hrkrshnn
hrkrshnn previously approved these changes Oct 6, 2021
Copy link
Contributor

@hrkrshnn hrkrshnn left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks. This is fine by me. I will wait to see what others in the team think about making the recommendation stronger.

docs/index.rst Outdated
version of Solidity. This is because breaking changes as well as
new features and bug fixes are introduced regularly. We currently use
a 0.x version number `to indicate this fast pace of change <https://semver.org/#spec-item-4>`_.
When deploying contracts, you should only use the latest released version of Solidity.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this reads (and has read before) a bit weird - maybe we should instead emphasize that you should use the latest version because only it is guaranteed to gets security fixes (sometimes we also fix older versions)?

@fulldecent
Copy link
Contributor Author

My goal here is to make this language as strong as the Solidity team will allow. My preference is:

Use the latest released version of Solidity for your projects. DO NOT USE older versions as they have known problems and/or may not receive fixes.

@chriseth
Copy link
Contributor

chriseth commented Oct 6, 2021

Totally fine, @fulldecent - my comment was mainly about restructuring the paragraph so that it is clearer why we only recommend the latest version.

cameel
cameel previously approved these changes Oct 15, 2021
Copy link
Collaborator

@cameel cameel left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the wording is ok now and the text does reflect our general policy.

@cameel
Copy link
Collaborator

cameel commented Oct 15, 2021

@fulldecent Can you squash your commits and rebase on the latest develop (which has a workaround for the failing b_osx job)?

@chriseth chriseth merged commit 863a0d3 into argotorg:develop Oct 19, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants