Skip to content
Security

Security policy

We take reports seriously and we publish what we fix. This page is the single source of truth for reporting a vulnerability.

Coordinated disclosure

Report vulnerabilities privately. We acknowledge within 3 business days and publish an advisory once a fix ships.

Supported versions

Security fixes are backported to the latest minor release. Older minors are best-effort only.

Transparent advisories

Every fixed vulnerability is documented publicly with affected versions, impact, and remediation.

How to report a vulnerability

Please do not open a public issue for a security problem. Email us instead:

security@vectorlogic.in

Placeholder: security@vectorlogic.in is a placeholder address and must be confirmed and provisioned by the COO before this site goes live. It is not a monitored mailbox today.

Encrypt sensitive reports if you can; ask for our PGP key in your first message and we will send it. Include the affected project and version, a description, and — where possible — a minimal reproduction and a suggested severity.

What happens next

  1. Acknowledgement within 3 business days.
  2. Triage and severity within 7 business days, with a first assessment shared with you.
  3. Fix and release as soon as is practical, weighed against the severity. Critical issues are prioritised over everything else.
  4. Public advisory published at the same time as the fix, crediting the reporter unless they prefer to remain anonymous.

Disclosure timeline

We follow coordinated disclosure. Our target is a fix and a public advisory within 90 days of a report, or sooner where the issue is severe. If we have not fixed an issue within 90 days, reporters are free to disclose publicly; we will not ask for silence beyond that window. We will always credit reporters who wish to be credited.

Supported versions

  • Latest minor release

    Fully supported. Security fixes are issued here first.

  • Previous minor release

    Security fixes are backported for 90 days after a new minor ships.

  • Older releases

    Best-effort only. We recommend upgrading to the latest minor release.

  • Pre-release / experimental builds

    Not supported for security fixes. Do not run them in production.

Scope

In scope: the source code in our repositories and the artifacts we publish. Out of scope: third-party dependencies (report those upstream, though we are glad to coordinate), and any service we do not operate.

Website privacy

This website collects nothing. See the privacy page for details.