Security fixes are applied to the latest released version on main. Older versions are not maintained.
| Version | Supported |
|---|---|
| latest | ✅ |
| < latest | ❌ |
Please do not report security vulnerabilities through public GitHub issues.
Instead, report them privately using one of the following channels:
- GitHub Security Advisories (preferred): use the Report a vulnerability button in the Security tab of this repository.
- Email:
andrea.za94@gmail.comwith subject[lcp][security] <short description>.
Please include:
- A description of the issue and its potential impact.
- Steps to reproduce, or a proof-of-concept if available.
- The affected version(s) and environment details.
- Your suggested mitigation, if any.
- You will receive an acknowledgement within 7 days.
- A fix or mitigation plan will be communicated within 30 days, depending on severity and complexity.
- Once a fix is available, a coordinated disclosure date will be agreed upon before any public release notes or advisories are published.
Thank you for helping keep lcp and its users safe.