Skip to content

Security: citry-dev/citry

Security

SECURITY.md

Security policy

Supported versions

Citry is pre-1.0 and moves fast, so security fixes land on the latest released version of each package. Please make sure you are on the newest citry and citry-core before reporting.

Package Supported
citry latest release
citry-core latest release

Reporting a vulnerability

Please do not open a public issue for security problems.

Report privately through GitHub's private vulnerability reporting: open the repository's Security tab and choose Report a vulnerability. That opens a private advisory visible only to the maintainers.

Include, as far as you can:

  • the affected package and version,
  • a description of the issue and its impact,
  • steps to reproduce (a minimal component or template is ideal), and
  • any known workaround.

What to expect

  • We aim to acknowledge a report within a few days.
  • Once the issue is confirmed we will work on a fix, coordinate a release, and keep you posted; we are happy to credit you in the release notes.
  • Please give us a reasonable window to ship a fix before any public disclosure.

There aren't any published security advisories