KaaS is pre-1.0 (latest release v0.1.0). There are no long-term support
branches yet, and no version other than the most recent release receives
security fixes. Fixes land on main and go out in the next release.
Once 1.0 ships, this section should name the supported minor versions.
Please report vulnerabilities privately through GitHub's private vulnerability reporting: open the repository's Security tab and choose Report a vulnerability. That opens a channel visible only to the maintainers.
Do not open a public issue or pull request for a security problem, and do not describe it in a public discussion — a KaaS instance can hold an organisation's internal knowledge base, so the details matter.
What to include, where you have it:
- what an attacker can do, and what access they need to start
- the steps to reproduce it
- the affected version or commit
- any logs or output that show the effect
If you are unsure whether something counts, report it anyway.