Skip to content

Latest commit

 

History

History
26 lines (15 loc) · 1.35 KB

File metadata and controls

26 lines (15 loc) · 1.35 KB

Security Policy

Horilla takes security seriously.

This file is on the v1 line (1.0 / master). That line is deprioritized for security support — fixes are considered case-by-case, with no guaranteed schedule. Prefer upgrading to Horilla HR v2 (2.0 / dev/v2.0). See Discussion #1127.

Reporting a vulnerability

Do not open a public GitHub issue or discussion for a security vulnerability. Do not disclose exploit details publicly until we have published a fix or explicitly agreed otherwise.

Use GitHub Private Vulnerability Reporting only:

  1. Open a private vulnerability report on this repository.
  2. Include enough detail to reproduce (affected version/branch, steps, impact).

We do not accept or triage security vulnerability reports by email.

The full current policy (supported versions, scope, CVE criteria) lives on the default branch:

Contact