Skip to content

Security: refringe/coffer

.github/SECURITY.md

Security Policy

Supported Versions

Security fixes are released against the latest published version of Coffer (the most recent ghcr.io/refringe/coffer image and the main branch). Older releases are not patched; please keep your deployment up to date.

Reporting a Vulnerability

If you discover a security vulnerability within Coffer, please email Refringe at me@refringe.com. Please do not open a public issue for security vulnerabilities.

You can expect an initial response within 48 hours acknowledging your report. All security vulnerabilities will be promptly addressed.

Bug Bounty

Coffer is an open-source project and does not offer a bug bounty program. We appreciate responsible disclosure and will credit reporters in the fix commit where appropriate.

There aren't any published security advisories