Skip to content

Security: larananas/lumen-json-rpc

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in this project, please report it privately.

  • Do not open a public GitHub issue.
  • Contact the maintainer directly via the repository's contact information (email or GitHub Security Advisories).
  • Do not publicly disclose the vulnerability before a fix is available.

What to Include

  • A clear description of the vulnerability.
  • Steps to reproduce the issue.
  • The affected version(s), if known.
  • Any potential impact assessment.

Response Timeline

  • Acknowledgment within 7 days.
  • Assessment and triage within 14 days.
  • A fix or mitigation will be prioritized based on severity.

Supported Versions

Security fixes target the latest stable release line. Older releases may not receive updates.

Scope

This policy covers the library's core runtime code (src/). Example handlers, documentation, and build tooling are out of scope for security advisories.

There aren't any published security advisories