Skip to content

Security: AtyaLibraries/Middleware

SECURITY.md

Security

Supported versions

Version Supported
Latest released major/minor Yes
Earlier major/minor versions No, unless explicitly listed in a security advisory
Prerelease builds No

Private disclosure

Do not open a public issue for a suspected vulnerability. In the affected repository, open the Security tab, select Advisories, and choose Report a vulnerability to create a private GitHub Security Advisory. Include the impact, affected versions, reproduction steps, and any proposed fix.

If the affected repository does not have private vulnerability reporting enabled, contact its maintainers privately and ask them to open a draft security advisory. Do not include vulnerability details in a public issue or discussion.

Response targets

The maintainers will acknowledge a complete report within 5 business days. Validation, remediation, and release timing depend on severity and complexity, but reporters will receive status updates through the private advisory.

CVE handling

For confirmed vulnerabilities, maintainers will coordinate a fix privately, request a CVE through GitHub when appropriate, publish patched packages, and release a GitHub Security Advisory with affected and fixed version ranges. Public disclosure occurs after a supported fix is available or on a mutually agreed disclosure date.

There aren't any published security advisories