Skip to content

Security: DataSQRL/sqrl

SECURITY.md

Security Policy

Supported Versions

Each major release is maintained on its own release-* branch. Security fixes are applied to main and backported to the latest release branch only.

Version Supported
0.11.x ✅
< 0.11 ❌

We recommend always running the latest release of DataSQRL.

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Instead, report them privately via GitHub Security Advisories. If you are unable to use GitHub, you can email us at security@datasqrl.com.

Please include as much of the following as you can:

  • A description of the vulnerability and its potential impact
  • Affected component(s) and version(s)
  • Steps to reproduce, or a proof of concept
  • Any suggested mitigation or fix

What to Expect

  • We will acknowledge your report within 5 business days.
  • We will investigate, keep you informed of our progress, and may ask for additional details.
  • Once a fix is available, we will publish a GitHub Security Advisory and credit you, unless you prefer to remain anonymous.

Please give us a reasonable amount of time to address the issue before any public disclosure.

There aren't any published security advisories