| Version | Supported |
|---|---|
| 2.x.x | ✅ |
| 1.x.x | ❌ |
| 0.17.x | ❌ |
| < 0.17 | ❌ |
If you have found a potential security threat, vulnerability or exploit in Quasar or one of its upstream dependencies, please DON’T create a pull-request, DON’T file a public issue on GitHub, DON’T mention it on Discord and DON’T create a forum thread.
DO report it privately through GitHub’s private vulnerability reporting (the “Report a vulnerability” button on this repository’s Security tab) — the report is visible only to you and the Quasar team, and we will work with you there to triage the issue, prepare a fix and, where appropriate, publish a security advisory crediting your finding. At the current time we do not have the financial ability to reward bounties, but in extreme cases will at our discretion consider a reward.
Official App Extensions and UI kits (@quasar/testing-*, @quasar/apollo,
@quasar/qcalendar, …) each live in their own repository under the
quasarframework organization — please
report through the Security tab of that specific repository instead. See
Report a vulnerability
for the full guidance; when in doubt, report it on this repository and we will
route it to the right maintainers.
You can apply to book the Quasar team’s security experts to perform a Security Audit for your project. Contact us to find out more about how to acquire, validate and publish an official timestamped and version-locked audit badge.