We intend to keep supporting latest version with support for all minor versions in the semantic versioning X.Y.Z
.
To report a security issue, please use the GitHub Security Advisory "Report a Vulnerability" tab.
Here is what to expect after the security concerned is raised. A Root cause analysis is conducted, if it is indeed a security vulnerability, comprising of following steps:
- Original vulnerability source and how to replicate it if possible.
- OWASP assessment and suggestions including alternatives
- Patch to fix the vulnerability through PR
- An Architectural Decision Record is created under
/docs/NNN-ARD.md