Security issues are taken very seriously, however severity and urgency are difficult to measure.
Strongbox is not a large or complex project so all security issues will be treated as equally severe and urgent.
Strongbox will support security updates for the current major version.
Strongbox may backport security updates for the previous major version.
All other major versions are unsupported.
Version | Supported |
---|---|
3.x.x | ✔️ |
2.x.x | ➖ |
1.x.x | ❌ |
0.x.x | ❌ |
To report a security issue, open a regular 'bug report' issue and fill in the sections.
Ensure the 'steps to reproduce' are filled out in detail. Optionally tag the issue with 'security'.
A security issue may be closed if it cannot be reproduced.