Only the latest release is supported. Older versions do not receive security fixes.
| Version | Supported |
|---|---|
| Latest release | Yes |
| Older releases | No |
If you have found a security vulnerability in this project, report it privately to security@obsidiansolutions.co.uk. Do not open a public issue for a security problem.
When you report a vulnerability, include:
- the repository or component where the vulnerability can be observed
- a brief description of the vulnerability
- the steps needed to reproduce the vulnerability
- non-destructive exploitation details
If you can, also include:
- the type of vulnerability, for example an OWASP category
- screenshots or logs that show the exploitation
We acknowledge every report and fix confirmed vulnerabilities within the targets below. The clock starts when we confirm the vulnerability.
| Severity | Acknowledge | Fix target |
|---|---|---|
| Critical | 1 working day | 7 days |
| High | 2 working days | 14 days |
| Medium | 5 working days | 30 days |
| Low | 5 working days | 90 days or next release |
This project follows responsible disclosure. We aim to fix confirmed vulnerabilities before public disclosure, and we credit the reporter unless they ask to stay anonymous.
When you investigate a vulnerability, you must not:
- break the law
- access unnecessary or excessive amounts of data
- modify data
- use high-intensity invasive or destructive scanning tools
- try a denial of service
- disrupt services or systems
- tell other people about the vulnerability before disclosure
- social engineer, phish or physically attack staff or infrastructure
- demand money to disclose a vulnerability