Skip to content

Security: heptau/pgarachne

SECURITY.md

Security Policy

Security is a top priority for PgArachne. We appreciate the efforts of security researchers and users who help us improve the safety of our project by identifying and reporting vulnerabilities.

Supported Versions

As an independent, open-source project maintained with limited resources, we do not have the capacity to backport security patches to older releases. Therefore, security updates are only provided for the latest stable version.

We strongly recommend that all users stay up-to-date with the latest release to ensure they have the most secure version of PgArachne.

Version Supported
Latest ✅
Older ❌

Reporting a Vulnerability

If you discover a security vulnerability in PgArachne, please do not open a public GitHub issue. Publicly disclosing a vulnerability before a fix is available puts our users at risk.

Instead, please report it privately by sending an email to: 📧 security@pgarachne.com

When reporting, please include as much information as possible:

  • A detailed description of the vulnerability.
  • Steps to reproduce the issue (a proof of concept if possible).
  • The potential impact of the vulnerability.
  • The version of PgArachne you tested against.

Response and Resolution Process

  1. Acknowledgment: We take all reports seriously. You will receive an initial response from us acknowledging your report within 3 days.
  2. Triage & Fix: We will investigate the issue and work on a fix. We may contact you for further clarification or to help test the patch.
  3. Release: Once the vulnerability is patched, we will release a new version of PgArachne.
  4. Disclosure: After the patch is publicly available, we will publish a security advisory. If you wish, we will gladly credit you for the discovery to recognize your contribution to the project's security.

Thank you for helping keep PgArachne secure!

There aren't any published security advisories