| Version | Supported |
|---|---|
| Latest release | Yes |
main |
Yes |
Older releases may receive security fixes at maintainer discretion.
Please report security vulnerabilities privately using GitHub Security Advisories:
https://github.com/gopherust-io/nats-console/security/advisories/new
Do not open a public issue, pull request, or discussion for vulnerability reports.
- Affected module version or commit
- Description of the vulnerability and impact
- Steps to reproduce, or a proof of concept if available
- We aim to acknowledge vulnerability reports within 7 days.
- We will investigate and work on a fix, and keep you informed of progress.
- Once a fix is released, we coordinate public disclosure. We typically ask reporters to wait 90 days from the initial report (or until a fixed release is available, whichever comes first) before public disclosure, unless we agree otherwise.
- We credit reporters in the advisory unless you request anonymity.
Thank you for helping keep this project and its users secure.
For the default branch (main), keep GitHub settings aligned with OpenSSF Scorecard:
- Require pull requests before merge (≥1 approving review)
- Require status checks (CI “Go” / “All checks passed”, CodeQL when listed)
- Disallow force pushes and branch deletion
- Include administrators in protection rules (or org rulesets)
- Enable Dependabot alerts/security updates, secret scanning, and code scanning