Security fixes are provided for the latest public release line of sqry.
If you are reporting a vulnerability, please confirm:
- the public version you tested
- the operating system and architecture
- whether the issue affects the CLI, LSP, MCP server, VS Code extension, or release artifacts
Do not open public GitHub issues for suspected vulnerabilities.
Instead, report security issues privately to:
oss@sqry.dev
Please include:
- a clear description of the issue
- reproduction steps or proof of concept
- impact assessment
- affected versions
- any mitigations or workarounds you have identified
We will acknowledge receipt, investigate, and coordinate disclosure once a fix or mitigation is available.
- We will triage reports as quickly as possible.
- We may ask follow-up questions or request a minimal reproduction.
- We prefer coordinated disclosure and will work with reporters on timing.
Reports are most helpful when they are specific to publicly released artifacts, the public source tree, or the extension/runtime contract used by end users.