Skip to content

Security: yannallain/rrule-kmp

SECURITY.md

Security policy

Supported versions

Until the project reaches a stable compatibility policy, security fixes are released only for the latest published version.

Version Security updates
Latest GitHub Release Supported
Older releases and unreleased snapshots Not supported

Upgrade to the latest release before reporting an issue that may already have been corrected.

Report a vulnerability privately

Do not open a public issue, pull request, or discussion for a suspected vulnerability. Use GitHub private vulnerability reporting so details and any coordinated fix remain private.

If private reporting is unavailable, email yann.allain@protonmail.com. Include:

  • the affected version and consumer platform;
  • a minimal reproduction or proof of concept;
  • the expected and observed behavior;
  • any known impact, prerequisites, or mitigations.

Please avoid including credentials, private production data, or other secrets in the report. The maintainer will acknowledge the report, assess its impact, and coordinate disclosure and a fixed release when appropriate.

There aren't any published security advisories