Skip to content

Security: shamaton/msgpackgen

SECURITY.md

Security Policy

Supported Versions

The latest release in the v1 series is the actively supported version.

Version Security support
Latest v1 release Supported
Earlier v1 releases Please upgrade; fixes are evaluated case by case
v0 Not supported

We recommend upgrading to the latest v1 release before reporting an issue that may already have been fixed.

Reporting a Vulnerability

Please report suspected vulnerabilities through GitHub's private vulnerability reporting.

Do not open a public issue or discussion for an undisclosed vulnerability. In your private report, include the following when possible:

  • The affected package and version
  • A description of the impact and attack scenario
  • Minimal steps or code needed to reproduce the issue
  • Any suggested mitigation or fix

If you are unsure whether an issue belongs to msgpackgen or the msgpack runtime library, report it privately to either repository. The maintainers will triage it appropriately.

Please do not include credentials, production data, or other secrets in the report.

The maintainers will review reports as availability allows. Response and fix timelines cannot be guaranteed and depend on the severity and complexity of the issue. Please allow time for investigation and coordinated disclosure before publishing details.

There aren't any published security advisories