| Version | Supported |
|---|---|
| 1.2.x | ✅ Supported |
| 1.1.x | ✅ Supported |
| 1.0.x | ✅ Supported |
| < 1.0 | ❌ No longer supported |
Please do not report security vulnerabilities through public GitHub issues.
Instead, report them privately through GitHub Security Advisories or by email to dev@fisherk2.com.
You should receive a response within 48 hours. If you do not receive a response, please follow up to ensure we received your original message.
- Acknowledgment — within 48 hours of report
- Triage — within 5 business days (confirm vulnerability and assess severity)
- Fix and Disclosure — timeline based on severity:
- Critical/High — patch released within 7 days
- Medium — patch released within 30 days
- Low — patch released in next regular release cycle
We follow coordinated disclosure:
- Reporters are credited in security advisories upon request
- Critical fixes are released as patch versions
- Security advisories are published via GitHub Security Advisories
- We coordinate the public disclosure date with the reporter