If you discover a security vulnerability in Verbara Platform, please report it responsibly.
Use GitHub's private vulnerability reporting:
- Go to the Security tab of this repository
- Click "Report a vulnerability"
- Provide a detailed description of the vulnerability
- Acknowledgment: Within 48 hours
- Initial assessment: Within 5 business days
- Fix timeline: Depends on severity (critical: ASAP, high: 2 weeks, medium: next release)
- Do not publicly disclose the vulnerability until a fix is available
- We will credit reporters in the CHANGELOG (unless anonymity is requested)
This policy covers:
- The Verbara Platform API host (
src/Verbara.Platform.Apiand allVerbara.Platform.*packages) - Published container images built from this repository
- Security issues in dependencies should be reported to the respective maintainers
- The
Verbara.Sdk.Pro.*packages consumed by this project (commercial, closed-source — report tolicensing@verbara.io) - Configuration issues in user deployments