You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Use this section to tell people about which versions of your project are
6
-
currently being supported with security updates.
5
+
We take security seriously and ask that any vulnerabilities be reported **privately**.
7
6
8
-
| Version | Supported |
9
-
| ------- | ------------------ |
10
-
| 5.1.x |:white_check_mark:|
11
-
| 5.0.x |:x:|
12
-
| 4.0.x |:white_check_mark:|
13
-
| < 4.0 |:x:|
7
+
* Please use [GitHub’s private vulnerability reporting feature](https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing) on this repository.
8
+
* Do **not** open a public issue or pull request for security-related matters.
14
9
15
-
## Reporting a Vulnerability
10
+
## Response
11
+
12
+
* We aim to acknowledge valid reports within **48 hours**.
13
+
* Once confirmed, we will work on a fix and notify you when it’s resolved.
14
+
* Please allow us time to address the issue before any public disclosure.
16
15
17
-
Use this section to tell people how to report a vulnerability.
16
+
## Notes
18
17
19
-
Tell them where to go, how often they can expect to get an update on a
20
-
reported vulnerability, what to expect if the vulnerability is accepted or
21
-
declined, etc.
18
+
* Public issues or PRs disclosing vulnerabilities may be closed for security reasons.
19
+
* Always keep your installation up to date with the latest release.
0 commit comments