Skip to content

Security: phpboyscout/afmpeg

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest minor release of afmpeg receives security updates.

Version Supported
Latest Yes
Older No

Reporting a Vulnerability

Please do not report security vulnerabilities through public issues.

Instead, report them via email to security@phpboyscout.uk. Include as much of the following as possible:

  • A description of the vulnerability
  • Steps to reproduce or a proof-of-concept
  • The affected version(s)
  • Any potential impact assessment

Response Timeline

  • Acknowledgement: within 48 hours of the report
  • Initial assessment: within 5 business days
  • Fix or mitigation: target within 30 days, depending on severity

You will receive updates as the issue progresses through triage, fix development, and release.

Disclosure Policy

We follow coordinated disclosure. Once a fix is released we will:

  1. Publish a security advisory
  2. Credit the reporter (unless anonymity is requested)
  3. Include details in the release changelog

We ask that reporters refrain from public disclosure until a fix is available or 90 days have passed, whichever comes first.

There aren't any published security advisories