20 lines
898 B
Markdown
20 lines
898 B
Markdown
# Security policy
|
|
|
|
## Reporting vulnerabilities
|
|
|
|
Do not report suspected vulnerabilities, exploit inputs, or sensitive logs in
|
|
public issues or pull requests. The planned reporting channel is GitHub Private
|
|
Vulnerability Reporting on the official public repository.
|
|
|
|
That repository and reporting channel are not available yet. Public release is
|
|
blocked until maintainers configure and test the private reporting channel and
|
|
replace this paragraph with its actual link. No response-time commitment is
|
|
currently offered. Do not assume that a public issue is a private channel.
|
|
|
|
## Supported versions
|
|
|
|
Version 0.1.0 is an unreleased candidate. There is no supported production
|
|
release yet. Dependency scans and regression tests are release checks, not a
|
|
guarantee that the validator is free of vulnerabilities. Validate suitability
|
|
for your deployment before using its results for routing decisions.
|