Skip to content

Latest commit

 

History

History
64 lines (46 loc) · 1.66 KB

File metadata and controls

64 lines (46 loc) · 1.66 KB

Security Policy

Supported Versions

Version Supported
4.1.x
4.0.x
< 4.0

Reporting a Vulnerability

DO NOT report security vulnerabilities through public GitHub issues.

Instead, please report them via:

What to Include

When reporting a vulnerability, please include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial Assessment: Within 1 week
  • Resolution Target: Depends on severity
    • Critical: 7 days
    • High: 14 days
    • Medium: 30 days
    • Low: 90 days

Disclosure Policy

We follow responsible disclosure:

  1. Reporter notifies maintainer privately
  2. Maintainer acknowledges and investigates
  3. Maintainer develops and tests fix
  4. Fix is released with security advisory
  5. Public disclosure after users have time to update

Security Best Practices for Users

  • Always use the latest stable version
  • Pin your dependencies with lock files
  • Review release notes before updating
  • Subscribe to GitHub security advisories for this repo