Skip to content

Security: lugassawan/rimba

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.9.x
< 1.9

Reporting a Vulnerability

Please do not file a public GitHub issue for security vulnerabilities.

The preferred channel is GitHub Private Vulnerability Reporting: open the Security tab of this repository and click Report a vulnerability. This keeps the report confidential until a fix is ready.

If Private Vulnerability Reporting is unavailable, email lugassawan@users.noreply.github.com with the details below.

What to Include

  • Affected version(s)
  • Step-by-step reproduction instructions
  • Expected vs. actual behavior
  • Your assessment of the potential impact

Triage Response

  • Acknowledgement: within 7 days of receipt
  • Patch target: within 30 days (complex issues may take longer; we will communicate timelines case-by-case)

Reporters will be credited in the release notes unless they request anonymity.

There aren't any published security advisories