Skip to content

Security: szhekpisov/diffyml

SECURITY.md

Security Policy

Supported Versions

Version Supported
Latest release Yes
Older releases No

Only the latest release receives security updates. Users should always upgrade to the most recent version.

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Preferred: GitHub Security Advisories

Report vulnerabilities via GitHub Security Advisories. This allows private discussion and coordinated disclosure.

Alternative: Email

If you cannot use Security Advisories, contact the maintainers listed in CODEOWNERS.

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Acknowledge: within 2 weeks
  • Assess: within 1 month
  • Fix: timeline depends on severity, communicated during assessment

Disclosure

We follow coordinated disclosure. Please allow us reasonable time to address the issue before any public disclosure.

There aren't any published security advisories