This document states ARSFI's commitment to providing security
updates for MacWinlink. It is a companion to the security policy
at SECURITY.md and the coordinated-vulnerability-disclosure
policy at CVD_POLICY.md.
Statement effective from: MacWinlink V1.0.0 general
availability release.
Governing regulation: EU Cyber Resilience Act (Regulation
(EU) 2024/2847), Article 13(8) — expected product lifetime.
.0 release.The 5-year floor meets the EU Cyber Resilience Act Article 13(8)
guidance for expected product lifetime. ARSFI may extend support
beyond the stated minimum on a case-by-case basis but does not
commit to doing so in advance.
MacWinlink comprises two applications with different distribution
channels but the same support-lifetime commitment:
org.arsfi.macwinlink): distributed through the Mac App Store.org.arsfi.macwinlink-helper): distributed as a signed andwinlink.org. Users must actively download and install updatedUsers who do not install the security updates we ship cannot
expect security fixes to reach them, regardless of the support
window this policy states. This mirrors how amateur radio
equipment maintenance works generally: the operator is responsible
for keeping their station current.
MacWinlink Helper coordinates the installation of several
third-party components that it does not itself distribute:
brew install
direwolf at the Helper's prompt.brew install
hamlib at the Helper's prompt.For these components, ARSFI's commitment is best-effort: when a
security-relevant upstream release is available, the Helper's
version resolvers or update prompts are updated in the next Helper
release to reflect it. ARSFI does not make guarantees about the
security posture of these upstream components themselves — those
guarantees belong to the upstream projects and (for VARA)
vendors. A full list of runtime-managed components is included
in each release's Software Bill of Materials (SBOM).
To illustrate the policy concretely, assuming V1.0.0 ships on
1 January 2027:
| Event | Date | V1.x status | V2.x status |
|---|---|---|---|
| V1.0.0 GA | 2027-01-01 | Supported | Not yet released |
| V1.x minimum-support floor | 2032-01-01 | Supported through this date at minimum | — |
| Hypothetical V2.0.0 GA | 2029-06-01 | Sunset window begins | Supported |
| V1.x sunset window ends | 2030-06-01 | End of life | Supported |
| V2.x minimum-support floor | 2034-06-01 | — | Supported through this date at minimum |
Because V1.x is committed to security updates through 2032-01-01
regardless of when V2.x ships, and because the V1.x sunset window
of 12 months extends past the V1.x minimum-support floor only if
V2.x ships after 2031-01-01, the effective V1.x end-of-life date
is whichever of (V1.0.0 + 5 years) or (V2.0.0 + 12 months) is
later. Users are never worse off than five years of security
support on the version they installed.
For the purposes of this policy, a security update is:
CVD_POLICY.md); orBug fixes with no security implication, protocol enhancements,
new radio support, UI improvements, and other non-security work
are not security updates and are not subject to this policy's
timelines.
Material changes to this policy will be published at
https://downloads.winlink.org/User%20Programs/MacWinlink/ and noted in
release notes. Changes will not shorten the security update
window for versions already placed on the market. If we
extend the support window for a specific version, we will announce
that separately.
This policy states ARSFI's commitment as the manufacturer under
the EU Cyber Resilience Act. It is not a warranty and does not
create additional obligations beyond those imposed by applicable
law. Users in jurisdictions with stronger consumer protection
laws retain those rights.
Last revised: 2026-08-24.