🚨 Security Policy

🏷️ Supported Versions

Only the latest release of Assets Guardian is supported. Security patches, bug fixes, and every other update land exclusively on the most recent version. We do not backport fixes or maintain older releases in parallel.

If you are running an older version, the fix is always the same: upgrade to the latest release.

Version

Supported

Latest release

βœ…

Any older

❌

πŸ“’ Reporting a Vulnerability

If you discover a security issue, please disclose it responsibly through GitHub’s private vulnerability reporting rather than opening a public issue.

  1. Go to the Security tab of this repository.

  2. Click Report a vulnerability to open a private security advisory visible only to you and the maintainers.

  3. Describe the issue, the affected version, and clear steps to reproduce it.

⚠️ Warning: This private channel is also used for Code of Conduct reports. If your report is about contributor behavior rather than a technical vulnerability, follow the Code of Conduct instead and prefix its title with [Code of Conduct]. Untitled or unprefixed reports are handled as security vulnerabilities.

We’ll get back to you as soon as possible and work with you to confirm and plan a fix for the issue.

Please note that we do not offer a bug bounty program.