| Version | Supported |
|---|---|
| Latest 0.x release | Yes |
| Older releases | No |
Pre-1.0, only the latest published 0.x release receives security fixes. If you are on an older version, upgrade first and confirm the issue reproduces.
Please do not report security vulnerabilities through public GitHub issues, discussions or pull requests.
Primary channel: use GitHub's private vulnerability reporting for this repository: go to the Security tab and choose "Report a vulnerability". Your report stays private between you and the maintainers.
Fallback: if you cannot use GitHub's private reporting, email security@stravica.ai.
In your report, include the affected version, a description of the issue, and reproduction steps or a proof of concept if you have one.
- We will acknowledge your report and keep you informed as we investigate and fix.
- We follow coordinated disclosure with a 90-day window: we ask that you do not publish details of the vulnerability until a fix is released or 90 days have passed since your report, whichever comes first.
- Once fixed, we will credit you in the release notes unless you prefer otherwise.
This is a small, actively maintained project. We do not run a bug bounty programme and do not publish a formal response-time SLA, but private reports are taken seriously and handled promptly.