Skip to content

Security: nielsbasjes/yauaa

.github/SECURITY.md

Security Policy

The Yauaa team takes security very seriously, and aim to resolve issues as quickly as possible. Building secure software is a continuous process, and can always be improved. As such we welcome reports on potential security vulnerabilities, as well as suggestions around hardening the software and our process.

Reporting a suspected vulnerability

It is important that suspected vulnerabilities are disclosed in a responsible way, and are not publicly disclosed until after they have been analysed and a fix is available.

To report a security vulnerability, send an email to yauaa-security@basjes.nl .

Do not open a public issue, send a pull request, or disclose any information about the suspected vulnerability publicly. If you discover any publicly disclosed security vulnerabilities, please notify us immediately through yauaa-security@basjes.nl .

Supported Versions

Depending on the severity of a vulnerability the issue may be fixed in the current major.minor release of Yauaa, or for lower severity vulnerabilities or hardening in the following major.minor release. Refer to the versions available on Maven central to find the latest release.

Automatic updates

We strongly recommend using tool like Renovate or Dependabot to get the latest versions of all your dependencies automatically as a pull request in Github or Gitlab.

Learn more about advisories related to nielsbasjes/yauaa in the GitHub Advisory Database