Skip to content

Security: codeacme17/launchrally

SECURITY.md

Security policy

Supported version

LaunchRally is Experimental. Security fixes are applied to the current 0.1.x P0 release line; older prerelease states are not supported.

Report a vulnerability privately

Use GitHub private vulnerability reporting. Do not open a public Issue or Discussion for a suspected vulnerability.

Include a minimal reproduction, affected version, impact, and suggested mitigation when available. Do not include real credentials, private repository contents, uploaded Report or Evidence files, or unrelated personal data. You should receive an acknowledgement through the private advisory within seven days. Public disclosure is coordinated only after a fix or agreed mitigation is available.

General safety questions that do not reveal a vulnerability may use GitHub Discussions.

There aren't any published security advisories