These are eight public repos that ship one product on one version, and they had drifted: freemkv-engine carried no LICENSE at all (GitHub reported its licence as none), two crates had no code of conduct, four had no contributing guide, and none had a security policy — so there was no private route to report a vulnerability in a disc-decryption tool. SECURITY.md names GitHub Security Advisories on each repo rather than an address, so there is nothing to keep in sync and no inbox to go stale.
564 B
564 B
Security Policy
Supported versions
| Version | Supported |
|---|---|
| 1.6.x | Yes |
| < 1.6 | No |
Only the current 1.6.x line receives security fixes.
Reporting a vulnerability
Report vulnerabilities privately through GitHub Security Advisories: https://github.com/freemkv/libfreemkv/security/advisories/new
Do not open a public issue for a security report. Include the affected version, steps to reproduce, and the impact you believe the issue has.
Response time
You will get an initial response within 7 days.