This template does not ship a versioned product. Downstream projects should replace this table with the versions they still patch.
| Version | Supported |
|---|---|
Latest main |
Yes |
Do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
If this repository has
private vulnerability reporting
enabled, use the Security tab → Advisories → Report a vulnerability
(or open /security/advisories/new on this repo).
That keeps the report attached to the project and lets maintainers collaborate on a draft advisory before public disclosure.
If private reporting is not enabled or you cannot use GitHub, email security@cloudzero.com.
- Type of issue (for example XSS, injection, or privilege escalation)
- Affected version, tag, commit, or URL
- Full paths of the relevant source files
- Any special configuration required to reproduce the issue
- Step-by-step reproduction instructions
- Proof of concept, if you can share one safely
- Impact, including how an attacker might exploit the issue
- Suggested mitigations, if you have them
After you submit a report, you can expect:
- An acknowledgment
- An assessment of the vulnerability and its impact
- Communication about the fix timeline
- Credit for your discovery (if you want it) when the issue is disclosed
Thank you for helping keep CloudZero and our users safe.