Skip to content

Security: MS3Inc/tavros

Security

SECURITY.md

Security Policy

Supported Versions

The version listed in galaxy.yml is the only supported release line. We do not back-port fixes to previous minor versions.

Version Supported
current galaxy.yml version Yes
anything older No

Reporting a Vulnerability

Please do not open a public issue for a security report.

Email the maintainers directly via GitHub's private vulnerability reporting on this repository.

Include:

  1. The Tavros version and the affected component (e.g. roles/kong).
  2. Reproduction steps or a proof-of-concept.
  3. The impact you have been able to demonstrate.

We will acknowledge receipt within 5 business days and aim to provide an initial assessment within 10 business days. Coordinated disclosure timelines are agreed on a per-report basis.

There aren't any published security advisories