This document says which versions receive security fixes and how to report a vulnerability privately.
Security fixes apply to the latest released version only; there is no back-port
line. main is best effort. Once the project reaches 1.0 this table will name a
supported minor line.
| Version | Supported |
|---|---|
| Latest release | ✅ |
| Older releases | ❌ |
main (unreleased) |
best effort |
Do not open a public issue for a security vulnerability. Report it privately through GitHub's private vulnerability reporting: https://github.com/FerroHEALTH/FerroPIX/security/advisories/new. You will get an acknowledgement within seven days. If that window passes with no response, public disclosure to protect other users is your call.