Skip to content

Security: lock14/collections

SECURITY.md

Security Policy

Supported Versions

We support security updates for the following versions of collections:

Version Supported
Latest
< 1.0

Reporting a Vulnerability

We take the security of collections seriously. If you discover a security vulnerability, please report it responsibly by following these steps:

  1. Do not report security vulnerabilities through public GitHub issues or discussions.
  2. Please use the GitHub Private Vulnerability Reporting feature on this repository.
  3. If private vulnerability reporting is unavailable, email the maintainer directly.

What to Include in Your Report

To help us triage and resolve the issue quickly, please include:

  • A detailed description of the vulnerability.
  • Steps to reproduce the issue or a minimal Go code reproducer.
  • Impact assessment (e.g. denial of service, memory corruption, unexpected data exposure).
  • Any suggested fixes or mitigations.

Response Timeline

  • We will acknowledge receipt of your vulnerability report within 48 hours.
  • We will provide a status update and estimated timeline for a fix within 7 days.
  • Once a fix is verified, a patch release and security advisory will be published.

There aren't any published security advisories