Security fixes target main and the newest published release when a compatible patch is possible.
Older releases are not supported. Updating to a newer Java or Spring Boot baseline may be required
when an upstream line no longer receives security fixes.
Do not open a public issue for an undisclosed vulnerability. Use GitHub private vulnerability reporting and include:
- the affected version or commit;
- reproduction steps or a proof of concept;
- the expected and observed impact; and
- any known mitigation.
You should receive an acknowledgement within seven days. Remediation targets are seven days for critical findings, 30 days for high findings, 90 days for medium findings, and 180 days for low findings. These are targets for a volunteer-maintained project, not guaranteed service levels.
Please keep the report confidential until a fix or coordinated disclosure is ready.