During the pre-v1.0 development phase, only the latest commit on the main branch receives security fixes.
| Version | Supported |
|---|---|
main (latest) |
✅ |
| Older commits | ❌ |
Please do not report security vulnerabilities through public GitHub issues.
Email the maintainers at tahta@impactscope.com with the subject line [SECURITY] <brief description>.
Include as much of the following as possible:
- Type of issue (e.g., SQL injection, authentication bypass, data exposure)
- The file(s) involved and their location in the source tree
- Steps to reproduce the issue
- Proof-of-concept or exploit code (if available)
- Potential impact
- Acknowledgement: within 48 hours
- Initial assessment: within 5 business days
- Critical patches: within 14 days of confirmation
We follow a coordinated disclosure process. We will notify you when a fix is deployed before any public disclosure.