Skip to content

Security: digitalbazaar/forge

SECURITY.md

Forge Security Policy

Supported Versions

  • In general, only the latest release version is supported.
  • Exceptions may be made to release patches to old versions if justified.

Reporting a Vulnerability

  • Please use the GitHub vulnerability reporting system if possible.
  • Help us help you.
  • Do your best to fill in the standard data.
  • Provide a proof-of-concept of the issue if possible.
  • A branch or patch with a test case integrated in the test system is better.
  • A branch or patch with a test case integrated in the test system and a potential fix is the best.
  • Forge covers many algorithms. If you can, please reference spec sections related to the report.

Contact

If you need assistance, or for other security related questions, please contact us:

Learn more about advisories related to digitalbazaar/forge in the GitHub Advisory Database