We only provide security fixes for the most recent release. Older releases are unsupported; upgrade to receive fixes.
Please report any vulnerabilities via one of the following methods:
- Create a security advisory on GitHub
- Send an e-mail to team@pelican.dev
Include steps to reproduce, affected versions, impact, and a proof of concept if available.
You can expect a response within 72 hours.
Please do not disclose vulnerabilities publicly until we have released a fix. We will acknowledge receipt and can credit researchers upon request.
All interactions around vulnerability reports are covered by our code of conduct.