The latest published version of autoremediator receives security fixes.
Older versions are not actively patched.
| Version | Supported |
|---|---|
| Latest | ✅ |
| Older | ❌ |
Please do not file public GitHub issues for security vulnerabilities.
Report vulnerabilities privately using GitHub's security advisory feature.
We will acknowledge the report within 5 business days and aim to publish a fix within 30 days of confirmation.
autoremediator makes outbound HTTPS requests to public security intelligence APIs as part of its core function:
api.osv.dev— OSV vulnerability recordsapi.github.com— GitHub Advisory Databaseservices.nvd.nist.gov— NVD CVSS contextwww.cisa.gov— CISA Known Exploited Vulnerabilitiesapi.first.org— FIRST EPSS exploit probability scorescveawg.mitre.org— CVE Services referencesadvisories.gitlab.com— GitLab Advisory Databasewww.kb.cert.org— CERT/CC vulnerability notesapi.deps.dev— deps.dev package metadataapi.securityscorecards.dev— OpenSSF Scorecard repository postureregistry.npmjs.org— npm package registry
These calls use read-only public APIs, carry no credentials, and are expected behavior. They can be monitored or blocked via network policy in controlled environments.