Skip to content

Security: FerroHEALTH/FerroPIX

Security

SECURITY.md

Security Policy

This document says which versions receive security fixes and how to report a vulnerability privately.

Supported versions

Security fixes apply to the latest released version only; there is no back-port line. main is best effort. Once the project reaches 1.0 this table will name a supported minor line.

Version Supported
Latest release ✅
Older releases ❌
main (unreleased) best effort

Reporting a vulnerability

Do not open a public issue for a security vulnerability. Report it privately through GitHub's private vulnerability reporting: https://github.com/FerroHEALTH/FerroPIX/security/advisories/new. You will get an acknowledgement within seven days. If that window passes with no response, public disclosure to protect other users is your call.

There aren't any published security advisories