Security fixes are provided for the current default branch and the latest stable release, when this repository publishes releases. Older releases are not supported; upgrade to a supported version before requesting a fix.
| Version | Supported |
|---|---|
| Default branch | Yes |
| Latest stable release | Yes |
| Older releases | No |
Do not open a public issue or pull request for a suspected vulnerability.
Report vulnerabilities privately to Red Hat Product Security at secalert@redhat.com. Include the affected version, environment, reproduction steps, potential impact, and whether the issue is already public, when known.
For secure-contact options and the current Red Hat coordinated vulnerability disclosure process, see Red Hat Security Contacts and Procedures.
Red Hat Product Security owns acknowledgement, triage, remediation coordination, and disclosure timing under its coordinated vulnerability disclosure process. This repository does not promise a separate response-time SLA. Please use the Red Hat contact above for status and escalation.