We are committed to maintaining the security of this repository and its associated software. As part of this commitment, we provide security updates for the most recent release. Currently, this library is in an experimental state and does not have a major release yet. This might not change for the near future, as there is still some work to be done. Until then, the versioning will stay at 0.x.x. The first major release will be 1.0.0. As long as there is no major release, we will only provide support for the most recent (minor) version.
We will try to follow the official compatibility policy of Go, which means that we will provide support for the recent two releases. As of writing these versions are 1.23.x and 1.22.x.
Older versions will not receive security updates or fixes.
If you discover a security vulnerability within this repository, please reach out to us immediately. We take all legitimate security concerns seriously and will do our best to address the issue as quickly as possible.
To report a security vulnerability, please follow these steps:
- Do not create a public GitHub issue for the vulnerability.
- Contact the code owner of this repository via the official SurrealDB Discord server with a detailed description of the vulnerability.
- Include steps to reproduce the vulnerability and any relevant information that could help us understand and address the issue.
- We will acknowledge your email within reasonable time and provide an expected timeline for addressing the vulnerability.
- Once we have addressed the vulnerability, we will release a new version as soon as possible and update the affected versions accordingly.
Please note that as we prioritize security, we kindly request that you refrain from publicly disclosing the vulnerability until we have had a chance to address it. We will make every effort to keep you informed about our progress and the resolution of the issue.
For updates on security-related issues, fixes, and new releases, you can watch this repository on GitHub. Additionally, you can subscribe to release notifications to stay informed about new versions and security updates.
Thank you for your cooperation and assistance in making our software secure.