crabster

Sécurité

Ce document n'existe qu'en un seul exemplaire dans le dépôt : les deux langues du site pointent sur le même texte.

{% raw %}

Reporting a vulnerability🔗

Do not open a public issue. Use GitHub's private reporting instead: Security → Report a vulnerability on the repository. The thread is private between you and the maintainers until an advisory is published, and it keeps the report, the fix and the disclosure in one place.

Expect an acknowledgement within a few days. If you have had no reply after a week, say so on the same thread — a missed notification is more likely than a decision not to answer.

What is in scope🔗

Crabster generates code, so a vulnerability can sit on either side of that line and the two are not equally severe:

What is not🔗

Supported versions🔗

Before 1.0, only the latest published version is supported. Fixes go out as a new release rather than as a patch to an older line. {% endraw %}