Skip to content

Security: open-wanderer/wanderer

SECURITY.md

Security Policy

Reporting a Vulnerability

Please report security vulnerabilities through GitHub Private Advisories. Do not open a public issue.

We will acknowledge your report within 72 hours and aim to release a fix within 60 days. If we need more time we will let you know. We will credit you in the advisory and changelog when the fix is published.

Scope

In scope:

  • Vulnerabilities in this codebase that would affect any self-hosted Wanderer instance

Out of scope:

  • wanderer.to and any other publicly hosted instances — do not test against servers you do not own or operate
  • Vulnerabilities in third-party dependencies — please report those upstream
  • Theoretical issues without a working proof of concept

Supported Versions

Only the latest release receives security fixes. We do not backport patches to older versions.

Learn more about advisories related to open-wanderer/wanderer in the GitHub Advisory Database