| Version | Supported |
|---|---|
| 0.2.x | Yes |
| < 0.2 | No |
If you discover a security vulnerability, please report it responsibly:
- Do not open a public issue.
- Email security@ronsse.dev with a description of the vulnerability, steps to reproduce, and any relevant logs or screenshots.
- You will receive an acknowledgment within 48 hours.
- We aim to provide a fix or mitigation within 7 days for critical issues.
Security reports are welcome for:
- The core
trellislibrary and all published packages (trellis_cli,trellis_api,trellis_sdk,trellis_workers) - The MCP server (
trellis-mcp) - The REST API (
trellis-api) - CI/CD configuration and published container images
We follow coordinated disclosure. Once a fix is available, we will:
- Release a patched version.
- Publish a GitHub Security Advisory.
- Credit the reporter (unless they prefer anonymity).