We provide security updates for the latest released main branch and the most recent tagged release.
| Version | Supported |
|---|---|
main |
✅ |
| latest tag | ✅ |
| older tags | ❌ |
Please report security issues privately.
- Email:
security@dopetask.dev - Include a clear description of the vulnerability, impact, and reproduction steps.
- Share any proof-of-concept in a private channel only.
- Acknowledgement within 3 business days.
- Initial triage outcome within 5 business days after acknowledgement.
- Ongoing status updates at least weekly until resolution or mitigation guidance is published.
The following are treated as security vulnerabilities:
- Confidentiality, integrity, or availability compromise.
- Supply chain compromise in dependencies or build/release pipeline.
- Determinism compromise that could alter packet execution outcomes or artifact trust.
Do not open public GitHub issues for unpatched vulnerabilities.