Horilla takes security seriously.
This file is on the v1 line (1.0 / master). That line is deprioritized for security support — fixes are considered case-by-case, with no guaranteed schedule. Prefer upgrading to Horilla HR v2 (2.0 / dev/v2.0). See Discussion #1127.
Do not open a public GitHub issue or discussion for a security vulnerability. Do not disclose exploit details publicly until we have published a fix or explicitly agreed otherwise.
Use GitHub Private Vulnerability Reporting only:
- Open a private vulnerability report on this repository.
- Include enough detail to reproduce (affected version/branch, steps, impact).
We do not accept or triage security vulnerability reports by email.
The full current policy (supported versions, scope, CVE criteria) lives on the default branch:
- Security reports: GitHub Private Vulnerability Reporting only
- Non-security questions: GitHub Discussions or the project’s normal support channels