X-Git-Url: https://git.openstreetmap.org/nominatim.git/blobdiff_plain/5bea0b6086e3f0ba427da52da4fac7240a118068..f2b2b2b92ca87fdf6ae8fcd7062db76ff4c42f51:/SECURITY.md diff --git a/SECURITY.md b/SECURITY.md index 41a6f2ef..a14eba13 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -9,10 +9,10 @@ versions. | Version | End of support for security updates | | ------- | ----------------------------------- | -| 3.7.x | 2023-04-05 | -| 3.6.x | 2022-12-12 | -| 3.5.x | 2022-06-05 | -| 3.4.x | 2021-10-24 | +| 4.4.x | 2026-03-07 | +| 4.3.x | 2025-09-07 | +| 4.2.x | 2024-11-24 | +| 4.1.x | 2024-08-05 | ## Reporting a Vulnerability @@ -36,4 +36,6 @@ incident. Announcements will also be published at the ## List of Previous Incidents +* 2023-11-20 - [SQL injection vulnerability](https://nominatim.org/2023/11/20/release-432.html) +* 2023-02-21 - [cross-site scripting vulnerability](https://nominatim.org/2023/02/21/release-421.html) * 2020-05-04 - [SQL injection issue on /details endpoint](https://lists.openstreetmap.org/pipermail/geocoding/2020-May/002012.html)