Citry is pre-1.0 and moves fast, so security fixes land on the latest
released version of each package. Please make sure you are on the newest
citry and citry-core before reporting.
| Package | Supported |
|---|---|
citry |
latest release |
citry-core |
latest release |
Please do not open a public issue for security problems.
Report privately through GitHub's private vulnerability reporting: open the repository's Security tab and choose Report a vulnerability. That opens a private advisory visible only to the maintainers.
Include, as far as you can:
- the affected package and version,
- a description of the issue and its impact,
- steps to reproduce (a minimal component or template is ideal), and
- any known workaround.
- We aim to acknowledge a report within a few days.
- Once the issue is confirmed we will work on a fix, coordinate a release, and keep you posted; we are happy to credit you in the release notes.
- Please give us a reasonable window to ship a fix before any public disclosure.