Each major release is maintained on its own release-* branch.
Security fixes are applied to main and backported to the latest release branch only.
| Version | Supported |
|---|---|
| 0.11.x | ✅ |
| < 0.11 | ❌ |
We recommend always running the latest release of DataSQRL.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, report them privately via GitHub Security Advisories. If you are unable to use GitHub, you can email us at security@datasqrl.com.
Please include as much of the following as you can:
- A description of the vulnerability and its potential impact
- Affected component(s) and version(s)
- Steps to reproduce, or a proof of concept
- Any suggested mitigation or fix
- We will acknowledge your report within 5 business days.
- We will investigate, keep you informed of our progress, and may ask for additional details.
- Once a fix is available, we will publish a GitHub Security Advisory and credit you, unless you prefer to remain anonymous.
Please give us a reasonable amount of time to address the issue before any public disclosure.