sqlcj is a pre-1.0 project and currently has no supported release line. Security fixes target the current code on the master branch.
Report suspected security vulnerabilities privately through GitHub private vulnerability reporting. Do not disclose vulnerabilities through public issues, pull requests, or discussions.
Please include, where applicable:
- the security impact and affected component;
- reproducible steps or a minimal schema, query, or configuration;
- relevant environment details, such as Java and database versions; and
- any suggested mitigation.
Do not include live credentials, personal data, or unrelated sensitive data in proof-of-concept material.
Maintainers will acknowledge the report and communicate through the private advisory as availability permits. After assessing the report and any fix, maintainers will coordinate publication through the advisory. No response or remediation time is guaranteed.
Ordinary defects without security impact belong in public issues.