Please report security issues privately so they can be triaged and fixed before public disclosure.
- dbt Labs responsible disclosure: dbt Labs Security Disclosure
- GitHub: If this repository is enabled for them, you may also use GitHub Security advisories for this repo.
Do not open a public issue for an undisclosed security vulnerability.
Security fixes are applied to the latest release line when practical. Use the most recent tagged release or the default branch for production-like workloads.