Skip to content

Security: magnusp/libsql-java

SECURITY.md

Security Policy

Reporting a Vulnerability

We take the security of libsql-java seriously. If you discover or suspect a security vulnerability, please report it privately rather than opening a public issue.

Preferred Reporting Method: GitHub Security Advisory

Please use GitHub's Private Vulnerability Reporting:

  1. Navigate to the Security tab of this repository: https://github.com/magnusp/libsql-java/security.
  2. Click on Report a vulnerability to open a draft advisory.
  3. Provide details of the issue including:
    • Steps to reproduce or proof-of-concept.
    • Affected version(s) or modules.
    • Potential impact of the vulnerability.

This will allow maintainers to review, collaborate with you on a patch, and coordinate responsible disclosure.

What to Expect

  • Acknowledgment: We aim to acknowledge receipt of security reports within 48 hours.
  • Assessment: We will investigate and assess severity.
  • Coordination & Release: Once a fix is verified, a patched release will be published along with a security advisory detailing the resolution.

There aren't any published security advisories