| Version | Supported |
|---|---|
| 0.x (pre-1.0) | Yes — fixes land on main |
| After 1.0 GA | The last two minor releases receive security backports for 12 months |
Please report vulnerabilities privately through GitHub Security Advisories. Do not open public issues for security reports.
You will receive an acknowledgment within 3 business days.
| Severity | Target |
|---|---|
| Critical | Fix released within 7 days |
| High | Fix released within 30 days |
This policy covers the published library modules and TCK, including their shipped
classifiers. The examples/ applications are demonstration code and are out of scope.
The release-candidate workflow resolves the actual publication runtime graphs, checks SBOM completeness (including shaded Caffeine and published test fixtures), and scans them with a checksum-pinned Trivy binary. Unexcepted HIGH/CRITICAL findings and incomplete or failed scans reject acceptance. Any checked-in exception must name the exact vulnerability/artifact/version, owner, rationale and future expiration date; exceptions require maintainer review.
The complete candidate evidence bundle is signed with Sigstore and receives GitHub build provenance. Its manifest binds binaries, classifiers, publication metadata, SBOMs and scan results to their exact SHA-256 bytes and source commit. Final-mode evidence is retained with an existing GitHub release; ordinary SNAPSHOT development and trial workflows remain allowed.
See release verification for checking signatures, manifest contents and published bytes. The maintainer procedure describes scanner self-tests, exception policy and evidence generation. A separately rebuilt artifact is not covered by the candidate attestation unless its checksum matches. Historical evidence applies only to its recorded artifacts and source commit; it does not certify a future release.
Application BOMs can override library versions; functional compatibility checks in the platform matrix do not replace scanning the final application dependency graph.