| Version | Supported |
|---|---|
| 0.0.x | ✅ |
Please report security vulnerabilities privately. Do not open public issues for security-sensitive bugs.
Email: security@crkg-schema.dev (placeholder — operational mailbox pending)
We aim to acknowledge receipt within 48 hours and provide an initial assessment within 5 business days. Critical vulnerabilities will receive priority handling.
We follow coordinated disclosure. Once a fix is prepared and released, we will publish a security advisory and credit the reporter (unless they wish to remain anonymous).