Skip to content

Security: niharnm/Semper

SECURITY.md

Security policy

Supported versions

Security fixes are made for the latest release and the current main branch. Older releases may not receive fixes.

Reporting a vulnerability

Do not open a public issue for an undisclosed vulnerability.

Use the repository's private vulnerability reporting form. This sends the report privately to the maintainers.

Include:

  • The affected version or commit.
  • Steps to reproduce the issue.
  • The expected security impact.
  • Any proof-of-concept files needed to confirm the report.
  • Whether you have disclosed the issue anywhere else.

You should receive an acknowledgment within seven days. Release timing depends on severity, confirmation, and the work required for a safe fix. Reporters who want public credit will be named in the advisory or release notes.

There aren't any published security advisories