The Neutral ecosystem is in early development and does not currently publish a stable, supported release line. Security fixes are generally made on the active development branch. Individual repositories may define more specific support policies; those policies take precedence.
Important
Please do not report vulnerabilities in a public issue, discussion, pull request, or commit.
- Open the affected repository and select Security.
- Use Report a vulnerability if private vulnerability reporting is enabled.
- If it is not available, open a public issue containing no vulnerability details and ask the maintainers to establish a private contact channel.
Include, when possible:
- the affected project, revision, and configuration;
- the type and potential impact of the vulnerability;
- reproduction steps or a minimal proof of concept;
- suggested mitigations; and
- whether the issue has been disclosed elsewhere.
Maintainers will acknowledge a private report when capacity allows, investigate it, and coordinate remediation and disclosure with the reporter. Because the ecosystem is currently volunteer-run and early-stage, no fixed response or resolution time is promised.
Please allow maintainers a reasonable opportunity to investigate and release a fix before public disclosure.