Skip to content

Security: CentralPing/.github

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in any CentralPing project, please report it responsibly through GitHub's private vulnerability reporting:

  1. Navigate to the affected repository on GitHub.
  2. Go to the Security tab.
  3. Click Report a vulnerability.
  4. Fill in the details and submit.

Alternatively, you can email [email protected].

Please do not open a public issue for security vulnerabilities.

Response Timeline

  • Acknowledgment: Within 48 hours of receiving your report.
  • Assessment: Within 7 days we will confirm the vulnerability and its impact.
  • Fix: We aim to release a patch within 30 days of confirmation.

Supported Versions

Project Supported Versions
ergo Latest minor
ergo-router Latest minor
json-api-query Latest minor

Only the latest minor release of each project receives security updates.

Disclosure Policy

We follow coordinated disclosure. Once a fix is released, we will publish a GitHub Security Advisory with full details.

There aren’t any published security advisories