This policy applies to every DragoAnt repository that does not ship its own SECURITY.md.
Fixes are released for the latest published version of each package. Older major versions get a fix only when the issue is severe and the upgrade path is not practical.
Report vulnerabilities privately through GitHub: open the affected repository's Security tab and choose Report a vulnerability. Please do not open a public issue, discussion or pull request for a vulnerability.
Include:
- the package name and version, and the target framework;
- a minimal reproduction (input, configuration, code);
- the impact you observed or expect.
- We acknowledge the report within 7 days.
- We confirm the issue, agree on a fix and a disclosure date with you, and keep you informed while we work on it.
- The fix ships as a new package version together with a published GitHub security advisory. You are credited unless you ask not to be.