Security policy
We take reports seriously and we publish what we fix. This page is the single source of truth for reporting a vulnerability.
Coordinated disclosure
Report vulnerabilities privately. We acknowledge within 3 business days and publish an advisory once a fix ships.
Supported versions
Security fixes are backported to the latest minor release. Older minors are best-effort only.
Transparent advisories
Every fixed vulnerability is documented publicly with affected versions, impact, and remediation.
How to report a vulnerability
Please do not open a public issue for a security problem. Email us instead:
security@vectorlogic.in
Placeholder: security@vectorlogic.in is a placeholder address and must be confirmed and provisioned by the COO before this site goes live. It is not a monitored mailbox today.
Encrypt sensitive reports if you can; ask for our PGP key in your first message and we will send it. Include the affected project and version, a description, and — where possible — a minimal reproduction and a suggested severity.
What happens next
- Acknowledgement within 3 business days.
- Triage and severity within 7 business days, with a first assessment shared with you.
- Fix and release as soon as is practical, weighed against the severity. Critical issues are prioritised over everything else.
- Public advisory published at the same time as the fix, crediting the reporter unless they prefer to remain anonymous.
Disclosure timeline
We follow coordinated disclosure. Our target is a fix and a public advisory within 90 days of a report, or sooner where the issue is severe. If we have not fixed an issue within 90 days, reporters are free to disclose publicly; we will not ask for silence beyond that window. We will always credit reporters who wish to be credited.
Supported versions
- Latest minor release
Fully supported. Security fixes are issued here first.
- Previous minor release
Security fixes are backported for 90 days after a new minor ships.
- Older releases
Best-effort only. We recommend upgrading to the latest minor release.
- Pre-release / experimental builds
Not supported for security fixes. Do not run them in production.
Scope
In scope: the source code in our repositories and the artifacts we publish. Out of scope: third-party dependencies (report those upstream, though we are glad to coordinate), and any service we do not operate.
Website privacy
This website collects nothing. See the privacy page for details.