Skip to content

Security: jsonlt/jsonlt-rust

SECURITY.md

Security policy

Supported versions

jsonlt-rust is currently in early development. Security updates apply to the latest version only.

Version Supported
0.x.x

Rust version support

jsonlt-rust supports Rust 1.70 and later (MSRV: 1.70).

See the Rust release schedule for the official release information.

Reporting a vulnerability

If you discover a security vulnerability in jsonlt-rust, please report it responsibly.

How to report

Do not open a public GitHub issue for security vulnerabilities.

Instead, please use GitHub's private vulnerability reporting feature:

  1. Go to the Security tab of the repository
  2. Click "Report a vulnerability"
  3. Fill out the form with details about the vulnerability

For more information, see Privately reporting a security vulnerability.

When reporting, please include:

  1. A description of the vulnerability
  2. Steps to reproduce the issue
  3. Potential impact assessment
  4. Any suggested fixes (optional)

What to expect

  • Acknowledgment - Expect acknowledgment of your report within 48 hours
  • Assessment - Investigation and severity assessment within 7 days
  • Resolution - Critical vulnerabilities receive fixes within 30 days
  • Disclosure - Disclosure timing coordinated with you

Security considerations

TBD

Security best practices

TBD

Acknowledgments

Thank you to the security research community for identifying and responsibly disclosing vulnerabilities.

There aren’t any published security advisories