Skip to content

Security: Coimbr/stumpless

Security

docs/SECURITY.md

Stumpless Security Policy

Supported Versions

The table below lists the current supported versions of Stumpless.

Version Supported
2.1.x ✔️
2.0.x ✔️
1.6.x ✔️
<= 1.5

Reporting a Vulnerability

If you discover a problem with Stumpless, please report it immediately to the project owner, Joel Anderson. The issue will be investigated as soon as possible and you will receive a response within 14 days of the message.

A fix will be deployed to all affected supported versions with a high priority. However, there is currently no guaranteed timeline for the patch as the project does not have any dedicated resources.

You can increase the speed and effectiveness of the response by including as much detail in your report as possible. Suggested fixes are welcome as well, though we ask that you keep your fixes limited to private correspondence until a fix can be deployed to limit the risk to users of the library in the meantime.

There aren’t any published security advisories