Version support policy
The Plone community actively maintains one major version of Plone. For security issues, support is greater: two major versions.
Definitions
Major version
- 2.5.x and 3.x are major versions of Plone
- 4.x will be major
- 5.x will be major.
Minor version
- 2.5.1, 2.5.2, 2.5.3, 2.5.4 and 2.5.5 are minor versions of Plone
- 3.1, 3.2 and 3.3 are minor
- 4.1 and 4.2 will be minor
- 5.1 will be minor.
development, bug fixes, refinements
Maintenance
Active maintenance applies to one major version.
Exception: periods of transition
Following the release of a major version, until the release of its minor version, two versions will be maintained:
- following the release of 4.0, active maintenance will apply to both 3.x and 4.0
- following the release of 4.1, active maintenance of 3.x will cease.
Security
Active security support applies to two major versions.
Exceptions
A security-related fix that is practical for the current major version may be impractical for previous versions. Example:
- the May 2008 hotfix for CVE-2008-0164 was included with the May 2008 release of Plone 3.1.1
- in the absence of a CSRF-related fix for 2.5.x, the documentation offers workarounds.
Community approaches to improvements and fixes
Plone is an open-source software project developed by hundreds of collaborators worldwide. Progress depends on the skills and interests of these people and others in the community.
Whilst there is no guarantee that any particular fix or development will be progressed, we believe that Plone has an excellent record in these areas. We invite your scrutiny and suggestions.