Skip to content

Security: verivus-oss/sqry

SECURITY.md

Security Policy

Supported Versions

Security fixes are provided for the latest public release line of sqry.

If you are reporting a vulnerability, please confirm:

  • the public version you tested
  • the operating system and architecture
  • whether the issue affects the CLI, LSP, MCP server, VS Code extension, or release artifacts

Reporting A Vulnerability

Do not open public GitHub issues for suspected vulnerabilities.

Instead, report security issues privately to:

  • oss@sqry.dev

Please include:

  • a clear description of the issue
  • reproduction steps or proof of concept
  • impact assessment
  • affected versions
  • any mitigations or workarounds you have identified

We will acknowledge receipt, investigate, and coordinate disclosure once a fix or mitigation is available.

What To Expect

  • We will triage reports as quickly as possible.
  • We may ask follow-up questions or request a minimal reproduction.
  • We prefer coordinated disclosure and will work with reporters on timing.

Scope Notes

Reports are most helpful when they are specific to publicly released artifacts, the public source tree, or the extension/runtime contract used by end users.

There aren't any published security advisories