Skip to content

Security: swimmesberger/Elarion

Security

SECURITY.md

Security Policy

Supported versions

Elarion is pre-1.0 and under active development. Security fixes are applied to the latest released version and the main branch. Until 1.0, please track the most recent release.

Version Supported
Latest release
main (preview)
Older prereleases

Reporting a vulnerability

Please do not open a public issue for security vulnerabilities.

Report privately through GitHub's private vulnerability reporting for this repository. If that is unavailable, email wimmesberger@gmail.com with the subject line Elarion security.

Please include:

  • a description of the vulnerability and its impact,
  • the affected package(s) and version(s),
  • steps to reproduce or a proof of concept,
  • any suggested remediation.

What to expect

  • Acknowledgement within 5 business days.
  • An assessment and, if confirmed, a plan and target timeline for a fix.
  • Coordinated disclosure: we will agree on a disclosure date and credit you in the release notes unless you prefer to remain anonymous.

Please give us reasonable time to release a fix before any public disclosure. Thank you for helping keep Elarion and its users safe.

There aren't any published security advisories