Meridian is pre-release software. There are no supported versions yet.
| Version | Supported |
|---|---|
| (none — pre-release, no tagged releases yet) | — |
This table will be maintained starting from the first tagged release.
Please do not open public GitHub issues for security vulnerabilities.
The preferred way to report a vulnerability is through GitHub Private Vulnerability Reporting on this repository ("Security" tab → "Report a vulnerability").
A dedicated security email address is TBD until public launch; until then, private vulnerability reporting on this repository is the only supported channel.
To help us triage and fix the issue quickly, please include:
- A description of the vulnerability and its potential impact
- The component affected (e.g. REST catalog API, maintenance service, console, MCP gateway) and the version or commit hash you tested against
- Step-by-step instructions to reproduce the issue, including any configuration required
- A proof-of-concept, exploit code, or example requests/responses, if available
- Any known workarounds or mitigations
- How you would like to be credited, if the report leads to an advisory
- Acknowledgement: within 3 business days of receiving a report
- Initial triage and severity assessment: within 7 business days
We will keep you informed of progress as we investigate and work on a fix.
We ask that you follow coordinated disclosure practices: please give us a reasonable opportunity to investigate and release a fix before any public disclosure of the vulnerability. We will coordinate with you on the disclosure timeline and, where applicable, publish a security advisory crediting the reporter (unless you prefer to remain anonymous).
There is currently no bug bounty program. We still greatly appreciate responsible reports and will credit reporters in advisories where appropriate.