Skip to content

Security: hypertrial/costguard

Security

SECURITY.md

Security policy

Supported versions

The latest stable 2.x release receives security fixes. Release candidates receive fixes until the corresponding stable release is published. v0.1.0 was the only earlier public release and is unsupported.

Reporting a vulnerability

Use GitHub private vulnerability reporting for hypertrial/costguard. Do not open a public issue for suspected vulnerabilities. Include affected versions, reproduction steps, impact, and any proposed mitigation.

The maintainers will acknowledge a report within seven calendar days and coordinate disclosure after a fix is available.

Release archives are accompanied by SHA-256 checksums, native smoke-test receipts, SBOM evidence, and GitHub artifact attestations bound to hypertrial/costguard.

There aren't any published security advisories