At every point in time only the most recent release is supported.
| Version | Supported |
|---|---|
| 0.9.3 | ✅ |
| < 0.9.3 | ❌ |
Please email me at tobiasbaeumer@gmail.com, since Github issues are public. PGP is possible, you know where to find my key - but it's not required.
After receiving your report, I will review it and create a GitHub Security Advisory (GHSA) to track the vulnerability privately. For critical findings I will also request a CVE identifier. You will be credited in the advisory unless you prefer to remain anonymous.
Once a vulnerability has been reported via email and coordinated with the maintainer, submit the fix as a pull request following the standard CONTRIBUTING guidelines with these additions:
- Reference the GitHub Security Advisory (GHSA) identifier in the PR description instead of a public issue (e.g.,
Refs GHSA-xxxx-xxxx-xxxx). If no advisory exists yet, reference issue #55 as a placeholder. - Do not include the full attack scenario in the public PR description until the advisory has been published. A brief note such as "Fixes a vulnerability disclosed privately — details in the security advisory" is sufficient until then.
- Once the advisory is published, the PR description should be updated to include the full rationale and attack scenario as required by CONTRIBUTING.
There are multiple published security advisories for these versions.
If you're running anything except 0.9.2 please update immediately!