Security updates are provided for the current v1 release line.
| Version | Supported |
|---|---|
| 1.x | Yes |
| < 1.0 | No |
Do not open a public issue or discussion. Report vulnerabilities through GitHub private vulnerability reporting.
Include:
- the affected prox version or commit;
- the deployment environment and relevant configuration, with secrets removed;
- a description of the impact and the security boundary crossed;
- minimal reproduction steps or a proof of concept;
- relevant logs, requests, or traces, with private data removed;
- any known workaround or suggested remediation.
Do not include live credentials, private keys, customer data, or access to production systems.
Reports are acknowledged within three business days. An initial assessment and next steps are normally provided within seven business days. Complex reports may require more time; updates are shared through the private advisory. Public disclosure is coordinated after a fix or mitigation is available.