Skip to content

Security: sabahattink/codediag

SECURITY.md

Security Policy

Supported versions

CodeDiag is currently pre-1.0. Security fixes are applied to the latest released version and the main branch.

Version Supported
Latest release Yes
Older releases No

Reporting a vulnerability

Please use GitHub private vulnerability reporting for suspected vulnerabilities. Include:

  • the affected version or commit;
  • reproduction steps or a minimal proof of concept;
  • the expected security impact;
  • any suggested mitigation, if known.

Do not include credentials, private source code, or sensitive user data in the report. Please allow a reasonable investigation period before public disclosure. Confirmed reports will receive a status update and remediation plan through the private advisory.

General bugs and analyzer false positives belong in the public issue tracker.

There aren't any published security advisories