crabster

Security

The repository holds a single copy of this document: both languages of this site point at the same text.

{% raw %}

Reporting a vulnerability🔗

Do not open a public issue. Use GitHub's private reporting instead: Security → Report a vulnerability on the repository. The thread is private between you and the maintainers until an advisory is published, and it keeps the report, the fix and the disclosure in one place.

Expect an acknowledgement within a few days. If you have had no reply after a week, say so on the same thread — a missed notification is more likely than a decision not to answer.

What is in scope🔗

Crabster generates code, so a vulnerability can sit on either side of that line and the two are not equally severe:

What is not🔗

Supported versions🔗

Before 1.0, only the latest published version is supported. Fixes go out as a new release rather than as a patch to an older line. {% endraw %}