We release patches for security vulnerabilities for the following versions:
| Version | Supported |
|---|---|
| latest | ✅ |
If you discover a security vulnerability, please report it by emailing the maintainers directly rather than opening a public issue.
Please do not report security vulnerabilities through public GitHub issues.
- Email: bartek@smykla.com
- GitHub Security Advisories: Use the "Security" tab in the relevant repository
Please provide as much information as possible about the vulnerability:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if available)
- Acknowledgment: We will acknowledge receipt of your vulnerability report within 48 hours
- Investigation: We will investigate and validate the reported vulnerability
- Fix: We will develop and test a fix
- Release: We will release a security update
- Disclosure: We will publicly disclose the vulnerability after the fix is released
Please allow time for the vulnerability to be fixed before public disclosure.
When contributing to Smykla Skalski projects:
- Keep dependencies up to date
- Never commit secrets, credentials, or API keys
- Use environment variables for sensitive configuration
- Follow the principle of least privilege
- Review code changes for security implications
We appreciate the security research community's efforts to responsibly disclose vulnerabilities.