All security issues in grammar2arbitrary should be reported publicly as bugs. Private reports will be made public by the maintainers after 7 days with best-effort attribution. Nevertheless, we will acknowledge security audits and publish vulnerability advisories for legitimate vulnerabilities.
This document should be considered expired after 2027-01-01. If you are reading this after that date, try to find an up-to-date version in the official source repository.
An advisory will be created only if a vulnerability affects at least one released versions of the project. The affected versions range of an advisory will by default include all unsupported versions of the project at the time of disclosure.
All advisories are listed in the table below, ordered most to least recent by publication date.
| ID | Date | Affected version(s) | Patched version(s) |
|---|---|---|---|
| - | - | - | - |
If you conduct a security audit of this project we would like to acknowledge it. If you found a security issue, you will be credited in the advisory. If you find nothing but the audit report is publicly available we will acknowledge it too.
We would like to publicly thank the following reporters:
- None yet