Skip to content

Security: pganalyze/libpg_query

Security

SECURITY.md

Security Policy

Supported Versions

See https://github.com/pganalyze/libpg_query#versions

Reporting a Vulnerability

Please report vulnerabilities privately by email to security@pganalyze.com.

We recommend encrypting your message using PGP for the pganalyze key, as documented on the pganalyze security page.

Note the pganalyze bug bounty program extends to libpg_query and related libraries if the bugs are exploitable, or can reasonably be deemed to be exploitable, in the context of the pganalyze application. If in doubt, reach out to security@pganalyze.com and we'd be happy to review and confirm, or provide a test account to confirm.

Learn more about advisories related to pganalyze/libpg_query in the GitHub Advisory Database