| Version | Supported |
|---|---|
| 20.x | ✅ |
| 19.x | {:white_check_mark: or :x:} |
| < 18.0 | ❌ |
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, report vulnerabilities through GitHub private vulnerability reporting for this repository.
If private vulnerability reporting is unavailable or unusable for your report, email the maintainers at mario@legioncodeinc.com.
When reporting a vulnerability, please include:
- The affected version, tag, or commit SHA
- A description of the issue and why you believe it is security-sensitive
- Steps to reproduce, or a proof of concept
- Any relevant logs, payloads, or screenshots
- The potential impact
- Any suggested mitigations or fixes, if known
You can expect an acknowledgment within {response_time, e.g. "3 business days"}.
After acknowledgment, we will assess the report and follow up with next steps. If the issue is confirmed, we will work on a fix and coordinate disclosure timing with the reporter when appropriate.
If a report is validated, we may publish a GitHub Security Advisory once remediation details are ready to share publicly.
{Optional: list what is in scope (this repository, a hosted service at a given URL) and what is explicitly out of scope. Delete this section for a simple single-repository project with no hosted service.}