| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
Do not open public issues for security vulnerabilities.
Report security issues to security@ironic.rs.
You should receive a response within 48 hours. If not, follow up to ensure receipt. We will keep you informed of the progress toward a fix and release.
- Type of vulnerability
- Steps to reproduce
- Affected versions
- Potential impact
- Suggested fix (if any)
We follow coordinated disclosure:
- Receive and confirm the report
- Work on a fix
- Release a patch
- Publicly acknowledge the report (with your consent)
cargo auditruns in CI on every pushcargo denychecks for advisories and license complianceunsafe_codeis forbidden at the workspace level- Secrets and credentials must never be committed — use environment variables or secret managers