The latest version will always receive security updates. Older versions, at this time, will not be maintained. New versions are expected to be backward compatible whenever possible.
Please report vulnerabilities in the Security Advisory Form per the GitHub docs
Vulnerabilities will always take highest priority and we try to respond same day to indicate we received the Vulnerability Advisory
Vulnerability Advisory communications:
- We will respond within 3 days to allow time to research the Advisory before indicating
if it's been accepted or declined
- If accepted, resolving the vulnerability will stay our highest priority and a
fix will be implemented as soon as possible (varies based on complexity)
- Once a fix has been implemented you will receive an additional update when the new release has been created
- If declined, the Advisory will be closed and no futher communication will occur
- If you feel this is in error, please report again referencing the previous Advisory and indicating an error
- If accepted, resolving the vulnerability will stay our highest priority and a
fix will be implemented as soon as possible (varies based on complexity)