Clarification on v2.x support lifecycle and security maintenance #7808
Closed
Davidvaquer
started this conversation in
General
Replies: 1 comment
-
|
Hey @Davidvaquer Yes, |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hi everyone,
We are currently evaluating Bruno for a large-scale deployment within a major corporate IT department (DSI) as an alternative to Postman.
Our security compliance team is inquiring about the support lifecycle of the v2.x branch. We noticed that recent CVE fixes (January 2026) were applied to the v3.0.0 release, while the v2 branch hasn't seen updates since December 2025.
Is the v2.x branch officially considered EOL (End of Life) regarding security patches?
Should new enterprise users target v3.x exclusively to ensure they are protected against known vulnerabilities (especially regarding the transition from vm2 to NodeVM)?
Getting an official word on this would greatly help us finalize our internal validation process. Thanks for this amazing tool!"
Beta Was this translation helpful? Give feedback.
All reactions