Security fixes are made against the latest released version of
hubuum_client. Reports affecting older releases are still welcome, but users
may need to upgrade to receive a fix.
Please report suspected vulnerabilities through GitHub private vulnerability reporting. Do not open a public issue for an undisclosed vulnerability.
Include as much of the following as possible:
- the affected version or commit;
- the expected and observed behavior;
- reproduction steps or a minimal proof of concept;
- the potential impact; and
- any suggested remediation.
You should receive an acknowledgement within seven days. The maintainer will coordinate validation, remediation, release timing, and public disclosure with the reporter. Please allow a reasonable remediation period before publishing details. Reporters will be credited when desired.
If a report does not describe a security vulnerability, it may be redirected to the public issue tracker.