Skip to content

Latest commit

 

History

History
42 lines (19 loc) · 1.82 KB

SECURITY.md

File metadata and controls

42 lines (19 loc) · 1.82 KB

Security Policy

Security policy of synthez crate (and its synthez-codegen and synthez-core sub-crates).

Supported versions

Before going 1.0, the synthez crate maintains only the most recent minor release.

Reporting a vulnerability

Security is of the highest importance and all security vulnerabilities or suspected security vulnerabilities should be reported to this project privately, to minimize attacks against current users of synthez crate before they are fixed. Vulnerabilities will be investigated and patched on the next patch (or minor) release as soon as possible. This information could be kept entirely internal to the project.

Private disclosure process

WARNING: Do not file public issues on GitHub for security vulnerabilities.

To report a vulnerability or a security-related issue, please use GitHub private vulnerability reporting on the Security Advisories page and fill the vulnerability details. It will be addressed within a week, including a detailed plan to investigate the issue and any potential workarounds to perform in the meantime. Do not report non-security-impacting bugs through this channel, use GitHub issues instead.

Public disclosure process

Project maintainers publish a public advisory to the community via GitHub.