| Version | Supported |
|---|---|
| Latest release | ✅ |
| Older releases | ❌ |
Please do not report security vulnerabilities through public GitHub issues.
Use GitHub's private vulnerability reporting:
- Go to the Security tab of the affected repository
- Click Report a vulnerability
- Fill in the details — include reproduction steps, impact assessment, and any suggested fix
Alternatively, email [email protected] for coordinated disclosure.
- Description of the vulnerability and affected component
- Steps to reproduce (proof-of-concept if applicable)
- Potential impact
- Any suggested mitigation or fix
| Stage | Target |
|---|---|
| Acknowledgement | Within 48 hours |
| Initial assessment | Within 5 business days |
| Resolution or workaround | Within 30 days for critical, 90 days for others |
We follow responsible disclosure principles. We will credit reporters in release notes unless you prefer to remain anonymous.
These projects implement controls aligned with the ASD Essential Eight and follow OWASP secure development guidelines. CI pipelines run automated SAST, dependency auditing, and secrets scanning on every pull request.