此内容来源于官方 Cosmos Security 仓库。**最后同步:**2026 年 4 月 27 日 | 查看源码

概述

本策略定义了 Cosmos Labs 如何对 Cosmos Stack 的核心组件进行维护与支持:
  • CometBFT
  • Cosmos SDK
  • Cosmos EVM
  • Inter-Blockchain Communication Protocol (IBC)
该发布流程旨在为使用 Stack 的开发者以及 Cosmos Labs 工程团队提供清晰性与可预期性。开发者应当明确知道哪些软件组合受到支持,并可用于生产环境。与此同时,Cosmos Labs 团队也可以围绕一组范围更小、定义明确的发布家族来协调修复、安全补丁和升级,从而实现更快的响应速度与更可预期的维护节奏。 为实现这一目标,我们引入了**发布家族(Release Families)**这一概念,即由 Stack 各组件版本组成的精选组合。每个家族都会经过完整测试,以验证兼容性、稳定性和长期支持能力。只有处于活跃状态的家族才会获得维护和缺陷修复。

发布家族

**发布家族(Release Family)**定义为一组特定的组件版本组合。 关于发布家族生命周期、当前支持窗口以及退役策略的权威信息来源,请参见发布家族页面。 本页面有意不重复列出生命周期时间线,以避免策略信息在多个页面之间出现偏差。

支持范围

  • **缺陷修复:**所有活跃家族都会获得关键安全问题和稳定性问题的补丁。
  • **兼容性:**保证同一家族内的所有组件可以协同工作。
  • **生命周期与退役:**生命周期窗口和退役细节维护在发布家族页面。
  • **可升级性:**我们保证从一个发布家族升级到其下一个相邻家族的升级路径,并通过清晰的指南、兼容性保证以及辅助工具来实现。

安全修复流程

如需详细了解 Cosmos Stack 的缺陷和漏洞处理方式,请阅读我们的安全策略。

生命周期终止(EOL)通知

发布家族当前及历史的 EOL 通知统一维护在发布家族页面,以便将生命周期策略集中在一个位置管理。
This content is sourced from the official Cosmos Security repository.Last sync: Apr 27, 2026 | View source

Overview

This policy defines how Cosmos Labs manages maintenance and support for the core Cosmos Stack components:
  • CometBFT
  • Cosmos SDK
  • Cosmos EVM
  • Inter-Blockchain Communication Protocol (IBC)
This release process aims to provide clarity and predictability to both developers using the Stack and the Cosmos Labs engineering team. Developers should know exactly which software combinations are supported and should be used in production. At the same time, the Cosmos Labs team can coordinate fixes, security patches, and upgrades across a smaller set of well-defined release families, allowing for faster response times and more predictable maintenance. To achieve this, we are introducing the concept of Release Families, curated sets of component versions of the Stack. Each family is fully tested for compatibility, stability, and long-term support. Maintenance and bug fixes are provided only for active families.

Release Families

A Release Family is defined as a specific combination of component versions. The canonical source of truth for release family lifecycle, active support windows, and retirement policy is the Release Families page. This page intentionally does not duplicate lifecycle timelines to avoid policy drift across multiple pages.

What Is Supported

  • Bug Fixes: Critical security and stability issues are patched for all active families.
  • Compatibility: All components within a family are guaranteed to work together.
  • Lifecycle and Retirement: Lifecycle windows and retirement details are maintained on the Release Families page.
  • Upgradability: We guarantee an upgrade path from one release family to the next adjacent family in the form of clear guides, compatibility guarantees, and tooling for assistance.

Security Fix Process

Please read our security policy for a detailed breakdown of how bugs and vulnerabilities are to be handled for the Cosmos Stack.

End of Life (EOL) Notices

Current and historical EOL notices for release families are maintained on the Release Families page to keep lifecycle policy centralized in one place.