We release patches for security vulnerabilities. Which versions are eligible for receiving such patches depending on the CVSS v3.0 Rating:
CVSS v3.0 | Supported Versions |
---|---|
9.0-10.0 | Releases within the previous six months |
4.0-8.9 | Most recent release |
Please report (suspected) security vulnerabilities via GitHub Security Advisories. From the repository's main page:
- Select "Security".
- In the "Reporting" section select "Advisories".
- Press the "New draft security advisory" button.
- Complete the security report.
You will receive a response from us within 48 hours. Once the issue is confirmed, we will release a patch as soon as possible depending on complexity but historically within a few days.