| Version | Supported |
|---|---|
| 1.x | ✅ |
| < 1.0 | ❌ |
Please do NOT report security vulnerabilities through public GitHub issues.
Instead, use GitHub Security Advisories to report vulnerabilities privately.
- Description of the vulnerability
- Steps to reproduce
- Impact assessment
- Suggested fix (if any)
| Stage | SLA |
|---|---|
| Acknowledgment | 48 hours |
| Assessment | 5 business days |
| Fix (critical) | 7 days |
| Fix (other) | 30 days |
This policy covers:
devtronicCLI package (packages/cli/)
This policy does not cover:
- Projects generated by devtronic (user responsibility)
- Third-party dependencies (report upstream)
We follow coordinated disclosure:
- Reporter submits vulnerability privately
- We acknowledge and assess
- We develop and test a fix
- We release the fix and publish an advisory
- Reporter receives credit (unless they prefer anonymity)
Thank you for helping keep devtronic and its users safe.