Security fixes are released for the latest 1.x release.
| Version | Supported |
|---|---|
| 1.3.x | ✅ |
| < 1.3 | ❌ |
If you are on an older release, upgrade to the latest 1.x before reporting.
Please do not report security issues through public GitHub issues.
Instead, report a vulnerability privately through GitHub. You will get an acknowledgement within 7 days. Please keep the report confidential until a fix is released.
This policy covers the akami gem, which builds WS-Security (wsse) headers for the savon SOAP client. For issues in another gem in the family (gyoku, httpi, nori, savon, wasabi), report to the affected repository in the savonrb organization. If you are not sure which gem is affected, report it here.