We release patches for security vulnerabilities in the latest version of each repo. If you are using an older version, please upgrade to the latest release.
Please do not report security vulnerabilities through public GitHub issues.
Instead, email us at security@valency.io with:
- A description of the vulnerability
- Steps to reproduce the issue
- The potential impact
- Any suggested fixes (if you have them)
We aim to acknowledge security reports within 5 business days. For critical issues we aim to provide a fix or mitigation within 30 days. More serious or actively-exploited issues take precedence and we'll communicate timing once we've assessed the report.
- We follow coordinated disclosure. We ask that you give us reasonable time to address the issue before making it public.
- We will credit reporters in the release notes (unless you prefer to remain anonymous).