In general, only the latest release of Ergo is supported (this is the latest release
on the releases page not marked as
a pre-release, or the latest tag in the semver ordering not marked as a release
candidate, or the current value of the stable branch).
We strive to provide a safe upgrade path for all deployments. In the interest of this, serious vulnerabilities will be patched from the latest stable release, bypassing unreleased changes in the master branch.
To receive updates about Ergo releases, including patches for security vulnerabilities, follow the project on GitHub or subscribe to our RSS feed: https://ergo.chat/feed.xml
If you have found a vulnerability, or a bug that you think may have security implications (in particular, denial of service, information disclosure, or authentication bypass), please report it privately instead of creating a public GitHub issue: https://github.com/ergochat/ergo/security/advisories/new