We take the security of kurl seriously. The following table lists the versions of kurl that are currently supported with security updates.
| Version | Supported |
|---|---|
| 1.x.x | ✅ |
| < 1.0 | ❌ |
If you discover a security vulnerability in kurl, please report it by opening a security advisory on GitHub or by emailing the maintainer directly. Please do not report security vulnerabilities through public GitHub issues.
To report a vulnerability:
- Go to the Security Advisories tab in the repository.
- Click Report a vulnerability to securely submit your findings.
- A description of the vulnerability.
- Steps to reproduce the issue (including any specific command flags or server configurations required).
- The version of
kurlyou are using. - Any potential impact this vulnerability might have on users.
We will strive to acknowledge your report within 48 hours and will provide a status update on the mitigation plan within 1 week.
Thank you for helping keep the kurl community secure!