Security fixes are applied to the latest release and to the hosted services. Self-hosted users should always run the most recent release.
| Version | Supported |
|---|---|
| Latest release | ✅ |
| Older releases | ❌ |
Please do not report security vulnerabilities through public GitHub issues, discussions or pull requests.
Report them privately through GitHub:
- Go to the Security tab of the affected repository.
- Click Report a vulnerability.
- Fill in the form.
Please include as much of the following as you can:
- The type of issue (for example SQL injection, XSS, broken access control, data exposure between users).
- The affected component, page or endpoint, and the version or commit.
- Step-by-step instructions to reproduce the issue.
- Proof-of-concept code, if available.
- The impact, and how an attacker might exploit it.
- Acknowledgement: within 3 business days.
- Initial assessment: within 7 business days.
- Fix: depending on severity. Critical issues affecting the hosted services are prioritised immediately.
You will be kept informed of progress. Once the issue is fixed, a GitHub Security Advisory is published, and you will be credited unless you prefer to stay anonymous.
In scope: the source code in these repositories and the hosted services built from it.
Out of scope: denial-of-service attacks, social engineering, spam, and automated scanner reports without a demonstrated impact. Please do not access or modify other users' data while testing; use your own accounts only.