Skip to content

Latest commit

 

History

History
33 lines (23 loc) · 915 Bytes

File metadata and controls

33 lines (23 loc) · 915 Bytes

Security Policy

Supported versions

Security fixes are provided for the 1.0.x stable line and, until 1.0.0 is tagged, for the latest 0.9.x line.

Version Supported
1.0.x yes
latest 0.9.x yes (until 1.0.0 is tagged)
older minor lines no
pre-0.1.0 commits no

Reporting a vulnerability

Do not open public GitHub issues for security vulnerabilities.

Use GitHub's private vulnerability reporting flow for this repository (Security tab -> Report a vulnerability).

Include:

  • affected commit/tag/version
  • reproduction steps or proof of concept
  • impact assessment
  • suggested mitigation (if known)

Response expectations

  • Initial triage acknowledgment target: within 7 days
  • Confirmed issues are fixed as soon as practical and documented in CHANGELOG.md
  • Public disclosure happens after a fix is available or a mitigation is documented