File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 1+ # Security Policy
2+
3+ ## Supported Versions
4+
5+ Only the latest version is supported, unless a maintained branch exists for an
6+ older major (e.g. ` 2.x.x ` ).
7+
8+ That said, if an unsupported version still has significant download numbers and
9+ you believe a vulnerability could have real impact, please report it anyway —
10+ it will be considered.
11+
12+ ## Reporting a Vulnerability
13+
14+ To report a security vulnerability, please use the
15+ [ Tidelift security contact] ( https://tidelift.com/security ) .
16+ Tidelift will coordinate the fix and disclosure.
17+
18+ When reporting, please include as much detail as possible:
19+
20+ - A description of the vulnerability and its impact
21+ - Steps to reproduce (a minimal reproduction is ideal)
22+ - Affected version(s)
23+ - Any suggested fix or mitigation, if you have one
24+
25+ ## What to Expect
26+
27+ - Acknowledgement of your report within a reasonable delay.
28+ - Confirmation of the issue and an assessment of its severity.
29+ - A fix released as soon as reasonably possible, with credit to the reporter
30+ (unless you'd rather stay anonymous).
31+
32+ This is an open source project maintained on a best-effort basis, so timelines
33+ may vary — thanks for your understanding, and for helping keep the ecosystem
34+ safe.
You can’t perform that action at this time.
0 commit comments