Security policy
Canonical GitHub source · Pulled from
SECURITY.mdat refmainduring this site build. Use Edit this page below to suggest a correction at the source.
Security policy
Section titled “Security policy”Supported versions
Section titled “Supported versions”Security fixes target the latest published Brand Navigation release and the
maintained d-compat/<YYYY>.<M> branches documented in the testing record.
Older commits and unsupported Discourse versions may not receive fixes.
Report a vulnerability
Section titled “Report a vulnerability”Report suspected vulnerabilities privately to security@codeworkslabs.dev. The mailbox is monitored by CodeWorksLabs.
Include the affected Brand Navigation release, branch, or commit; the Discourse version; a description of the impact; and reproducible steps or a minimal proof of concept where safe. Do not include credentials, personal data, production secrets, or unrelated private information.
Do not open a public GitHub issue for a vulnerability that has not been disclosed safely. CodeWorksLabs will confirm receipt, assess the report, and coordinate remediation and disclosure with the reporter as appropriate.
Use GitHub Issues for non-sensitive bugs, compatibility reports, configuration questions, and feature requests.