Skip to content

Security: gudcks0305/jev-java

SECURITY.md

Security Policy

Supported versions

The current 0.1.x release line receives security fixes until a newer release line supersedes it. Development snapshots and older superseded versions are not separately supported.

Reporting a vulnerability

Report vulnerabilities privately through GitHub Security Advisories. Do not open a public issue for an undisclosed vulnerability.

Include the affected version and module, provider and transport when relevant, Java and Spring Boot versions, impact, and a minimal sanitized reproduction. Never include API keys, authorization headers, real customer state, or other secrets. If logs are necessary, redact request and response bodies unless the specific field is essential to reproduce the issue.

The maintainer will coordinate investigation and disclosure through the private advisory. No response or fix deadline is guaranteed.

There aren't any published security advisories