Skip to content

Security: vltpkg/vltpkg

Security

SECURITY.md

Security Policy

Supported Versions

Security fixes land on the >=1.0.0 release line only. Pre-1.0 and pre-release versions (-rc, etc.) are not supported.

Reporting a Vulnerability

Email security@vlt.sh. Do not open a public issue.

Include the affected version, impact, and steps to reproduce.

Confirmed issues are fixed on a supported release. Where warranted we publish a GitHub Security Advisory, crediting the reporter unless asked otherwise.

Reporters are expected to follow our Code of Conduct.

There aren't any published security advisories