Skip to content

Conversation

@nmicht
Copy link
Collaborator

@nmicht nmicht commented Jul 3, 2025

Context

We have received security reports related to quiche demo applications. By design quiche-server and other quiche demo apps are not intended for to be used in production environments. Those offer no performance, security or reliability guarantees.

About this change

We want to update the README to be intentionally clear about this.

  • A section for disclaimers and notes is being added to the Readme.
  • Also, a paragraph just before the first example using quiche-server has been added.

@nmicht nmicht requested a review from a team as a code owner July 3, 2025 10:35
README.md Outdated
⚠️ Disclaimers & Notes
---------

* quiche-server is only a demo—for testing and examples. It is not production-ready and offers no performance, security or reliability guarantees.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
* quiche-server is only a demo—for testing and examples. It is not production-ready and offers no performance, security or reliability guarantees.
* quiche-server is only for testing and examples. It is not production-ready and offers no performance, security or reliability guarantees.

Copy link
Contributor

@evanrittenhouse evanrittenhouse Jul 3, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is there a benefit having this here and above?

README.md Outdated

* quiche-server is only a demo—for testing and examples. It is not production-ready and offers no performance, security or reliability guarantees.

* FFI/C examples and server tools are proof-of-concept, intended to guide usage rather than serve in production.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
* FFI/C examples and server tools are proof-of-concept, intended to guide usage rather than serve in production.
* FFI/C examples and server tools are proof-of-concept, intended to guide usage rather than serve production traffic

@nmicht
Copy link
Collaborator Author

nmicht commented Jul 11, 2025

From @LPardue - We need to generalise the statement more - any binary we include in the quiche project has no performance, security or reliability guarantees.

@LPardue LPardue changed the title DRAFT: add disclaimer for quiche-server Update docs to add disclaimer for quiche example binaries Jan 13, 2026
Co-authored-by: Julien Rouviere <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants