If you discover a security vulnerability in Zap, please report it responsibly:
- Do not open a public issue for security vulnerabilities
- Email security concerns to: security@zap-lang.dev (replace with actual contact)
- Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgment: within 48 hours
- Initial assessment: within 7 days
- Fix timeline: depends on severity
- Critical: 1-2 weeks
- High: 2-4 weeks
- Medium: 1-2 months
- Low: next scheduled release
- We follow coordinated disclosure
- We will credit reporters (unless anonymity is requested)
- We publish security advisories with each release
| Version | Supported |
|---|---|
| 2.x | Yes |
| 1.x | No |
| < 1.0 | No |
- Latest
v2.11.x - See releases/tag/v2.11.18 for details.