| Version | Supported |
|---|---|
| 1.x (latest) | Yes |
Please do not report security vulnerabilities through public GitHub Issues.
To report a security issue, email us at: security@umbrellaframe.dev
Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fix
We will respond within 72 hours and aim to release a patch within 7 days for confirmed critical issues.
This policy covers:
- The core SQL generation engine
- All provider packages
- The Roslyn Analyzer package
Out of scope:
- Vulnerabilities in third-party dependencies
- Issues in documentation