jwt/SECURITY.md

20 lines
904 B
Markdown
Raw Permalink Normal View History

2022-05-28 19:40:34 +03:00
# Security Policy
## Supported Versions
2024-11-04 09:57:43 +03:00
As of November 2024 (and until this document is updated), the latest version `v5` is supported. In critical cases, we might supply back-ported patches for `v4`.
2022-05-28 19:40:34 +03:00
## Reporting a Vulnerability
2024-11-04 09:57:43 +03:00
If you think you found a vulnerability, and even if you are not sure, please report it a [GitHub Security Advisory](https://github.com/golang-jwt/jwt/security/advisories/new). Please try be explicit, describe steps to reproduce the security issue with code example(s).
2022-05-28 19:40:34 +03:00
You will receive a response within a timely manner. If the issue is confirmed, we will do our best to release a patch as soon as possible given the complexity of the problem.
## Public Discussions
Please avoid publicly discussing a potential security vulnerability.
Let's take this offline and find a solution first, this limits the potential impact as much as possible.
We appreciate your help!