Skip to content

Security: cubic-vm/cubic

SECURITY.md

Security Policy

Supported Versions

Security fixes are applied to the main branch and the latest release. Older releases do not receive backported security patches.

Version Supported
main
latest release
older releases

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

If you discover a security vulnerability, please report it privately so that it can be assessed and fixed before public disclosure. You can report a vulnerability through GitHub's private vulnerability reporting:

https://github.com/cubic-vm/cubic/security/advisories/new

Please include as much of the following information as possible to help us understand and reproduce the issue:

  • A description of the vulnerability and its potential impact
  • The affected version(s)
  • Step-by-step instructions to reproduce the issue
  • Any relevant logs, screenshots, or proof-of-concept code

Response Process

  1. We will acknowledge receipt of your report.
  2. We will investigate and keep you informed of our progress.
  3. Once a fix is ready, we will coordinate a release and public disclosure with you.

We appreciate your effort in responsibly disclosing security issues and helping to keep Cubic safe for everyone.

There aren't any published security advisories