Skip to content

Security policy

Reporting a vulnerability

Please report security issues privately to Lambda Twelve rather than through a public issue. Use GitHub's private vulnerability reporting on this repository ("Report a vulnerability" under the Security tab). Include the affected version, a description of the issue and, where possible, a proof of concept.

You will receive an acknowledgement within five working days. We aim to publish a fix and a security advisory within 90 days of the report, sooner for issues that are being exploited.

Scope

In scope: everything under src/ and bin/ of this package, including the RS256 JWT verifier, the client-credentials token endpoint, the JSON-LD parser, the change applier and every HTTP endpoint of the PSR-15 server.

Out of scope: the wrapper packages (report those to their own repositories), NE:ONE, and deployments of this package by third parties.

Supported versions

Before 1.0.0, only the latest pre-release (1.0.0-betaN, then 1.0.0-rcN) receives security fixes. From 1.0.0 on, the latest minor release of the current major version is supported.