Security updates are provided on a best-effort basis for the latest release of each supported major version (v6, v7, v8, and v9).
If you believe you have found a security vulnerability, please open an issue at https://github.com/KromDaniel/rejonson/issues and include "[security]" in the title so we can triage it quickly. We aim to acknowledge new reports within 5 business days.
Please include:
- A description of the vulnerability and the potential impact.
- Steps to reproduce or proof-of-concept code, if available.
- Any known mitigations or workarounds.
We will coordinate with you to investigate and remediate the issue as quickly as possible. Once a fix is available and released, we will credit you unless you request otherwise.