We take the security of ElasticLoom projects seriously and appreciate
responsible disclosure. A project may have its own SECURITY.md describing
its scope and supported versions; where the two differ, the project's file
takes precedence.
Please do not open a public issue, discussion or pull request for security vulnerabilities.
Report vulnerabilities privately through GitHub's private vulnerability reporting:
- Go to the Security tab of the affected repository.
- Click Report a vulnerability.
Please include:
- a description of the issue and its impact;
- the affected project and version or commit;
- steps to reproduce, or a proof of concept;
- relevant details of your environment.
We aim to acknowledge reports within 7 days and to agree on a disclosure timeline with the reporter. We are happy to credit reporters in the published advisory unless you prefer to remain anonymous.
Unless a project states otherwise, security fixes are made to its latest release.