Skip to content

Security: CodesWhat/drydock

SECURITY.md

Security Policy

Supported Versions

Version Supported
Latest stable release
Latest release candidate on the active train
Older stable or prerelease versions

Security fixes for an active prerelease train are delivered in its next release candidate and carried into the next stable release. Older release candidates are not patched; upgrade to the newest candidate before reporting or validating a fix. Release candidates are pre-GA test builds and are not recommended as a substitute for the latest stable release in production.

Reporting a Vulnerability

If you discover a security vulnerability in drydock, please report it responsibly.

Do not open a public GitHub issue for security vulnerabilities.

Instead, please email security@getdrydock.com or use GitHub's private vulnerability reporting.

You can expect:

  • Acknowledgement within 48 hours
  • Status update within 7 days
  • Fix or mitigation as soon as feasible, depending on severity

We appreciate responsible disclosure and will credit reporters in the release notes (unless you prefer to remain anonymous).

There aren't any published security advisories