Security fixes are provided for the latest minor release line.
| Version | Supported |
|---|---|
| 1.3.x | ✅ |
| < 1.3 | ❌ |
We take the security of errx seriously. If you believe you have discovered a vulnerability, please do not disclose it publicly via public GitHub issues, pull requests, or discussions.
Please report vulnerabilities confidentially through GitHub's Private Vulnerability Reporting.
When submitting a security report, please include:
- A clear description of the vulnerability and its potential impact
- Affected package(s) or functions (for example
core,json, orstacktrace) - Steps to reproduce or a minimal proof-of-concept example
- Environment details (Go version, operating system, architecture)
- Any proposed remediation or patch, if available
- Acknowledgment: We aim to acknowledge receipt of your report within 48 hours.
- Investigation: We will verify the report, assess its severity, and keep you informed of our progress.
- Remediation: Once a fix is prepared and verified, we will release a patch release and publish a security advisory giving appropriate credit to the reporter.