Until Open Grid reaches 1.0, security fixes are provided for the latest published
minor release only. Users should reproduce a report against the latest release or
the current main branch when possible.
| Version | Supported |
|---|---|
| Latest 0.x minor | Yes |
| Older 0.x minors | No |
Use GitHub's private security advisory form. Do not open a public issue for a suspected vulnerability.
Include the affected package and version, impact, reproduction steps or a minimal case, and any known mitigation. Remove credentials and private data. A maintainer will aim to acknowledge a complete report within seven days and will coordinate validation, remediation, and disclosure through the advisory. Timing depends on severity and the complexity of a compatible fix.
If private vulnerability reporting is unavailable in the repository, contact the repository owner privately and ask for a secure reporting channel without including vulnerability details in the initial message.