Skip to content

Latest commit

 

History

History
16 lines (8 loc) · 1.03 KB

SECURITY.md

File metadata and controls

16 lines (8 loc) · 1.03 KB

Security Policy

This security policy applies to all projects under the Caikit organization on GitHub.

Supported Versions

The Caikit project provides community support only for the last minor version: bug fixes are released either as part of the next minor version or as an on-demand patch version. Independent of which version is next, all patch versions are cumulative, meaning that they represent the state of our main branch at the moment of the release. For instance, if the latest version is 0.10.0, bug fixes are released either as part of 0.11.0 or 0.10.1.

Security fixes are given priority and might be enough to cause a new version to be released.

Reporting a Vulnerability

To report a security issue, please email caikit.security@caikit.org with a description of the issue, the steps you took to create the issue, affected versions, and if known, mitigations for the issue.

Our security team will acknowledge receiving your email within 3 working days. It follows a 90 day disclosure timeline.