Skip to content

Security: dcadolph/switchtender

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Report suspected vulnerabilities privately to security@switchtender.com. Do not open a public issue for a security problem.

Include as much as you can:

  • A description of the issue and its impact.
  • Steps to reproduce, or a proof of concept.
  • The affected version, commit, or configuration.

You will get an acknowledgment within a few business days. Once a fix is ready, a patched release goes out, and the report is credited unless you prefer to stay anonymous.

Supported versions

Security fixes land on the latest 1.x release. Older versions are not patched.

Scope

The server, the CLI, the SDK, and the official container image and Helm chart are in scope. Report issues in third-party dependencies upstream, though a heads-up here is welcome.

There aren't any published security advisories