Skip to content

Security: jsonlt/jsonlt-ruby

SECURITY.md

Security policy

Supported versions

jsonlt-ruby is currently in early development. Security updates apply to the latest version only.

Version Supported
0.x.x

Ruby version support

jsonlt-ruby supports Ruby versions that have not reached end-of-life (EOL). When a Ruby version reaches EOL, the next minor release drops support for that version.

Supported versions start at Ruby 3.2

See the Ruby Maintenance Branches page for the official EOL schedule.

Reporting a vulnerability

If you discover a security vulnerability in jsonlt-ruby, please report it responsibly.

How to report

Do not open a public GitHub issue for security vulnerabilities.

Instead, please use GitHub's private vulnerability reporting feature:

  1. Go to the Security tab of the repository
  2. Click "Report a vulnerability"
  3. Fill out the form with details about the vulnerability

For more information, see Privately reporting a security vulnerability.

When reporting, please include:

  1. A description of the vulnerability
  2. Steps to reproduce the issue
  3. Potential impact assessment
  4. Any suggested fixes (optional)

What to expect

  • Acknowledgment - Expect acknowledgment of your report within 48 hours
  • Assessment - Investigation and severity assessment within 7 days
  • Resolution - Critical vulnerabilities receive fixes within 30 days
  • Disclosure - Disclosure timing coordinated with you

Security considerations

TBD

Security best practices

TBD

Acknowledgments

Thank you to the security research community for identifying and responsibly disclosing vulnerabilities.

There aren’t any published security advisories