| Version | Supported |
|---|---|
| 0.2.x | Yes |
| 0.1.x | No |
Do not open a public issue for security vulnerabilities.
Please report security vulnerabilities through GitHub's private vulnerability reporting:
- Go to the Security Advisories page
- Click "Report a vulnerability"
- Fill in the details of the vulnerability
You will receive an acknowledgment within 48 hours. We will work with you to understand the scope and develop a fix before any public disclosure.
This policy applies to:
- The tila Worker and Durable Object backend
- The tila CLI
- The tila SDK and MCP server
- Authentication and token handling
We accept vulnerability reports in English.