Skip to content

Security: BerliozFramework/Berlioz

SECURITY.md

Security Policy

Supported versions

Version Supported
3.x Yes
< 3.0 No

Reporting a vulnerability

If you discover a security vulnerability within the Berlioz Framework, please do not open a public issue.

Instead, please use GitHub's built-in vulnerability reporting:

  1. Go to the Security tab of this repository.
  2. Click "Report a vulnerability".
  3. Fill in the advisory form with as much detail as possible.

When reporting, please include:

  • A clear description of the vulnerability.
  • Steps to reproduce the issue or a proof of concept.
  • The affected package(s) and version(s).
  • The potential impact of the vulnerability.

What to expect

  • You will receive an acknowledgment within 48 hours.
  • We will collaborate with you directly in the GitHub Security Advisory to understand and verify the issue.
  • A fix will be prepared and released as soon as possible, depending on the severity.
  • You will be credited in the release notes (unless you prefer to remain anonymous).

Disclosure policy

We follow a coordinated disclosure process:

  1. The vulnerability is reported privately.
  2. We confirm the issue and develop a fix.
  3. A new release is published with the fix.
  4. The vulnerability is publicly disclosed after the fix is available.

We ask that you do not publicly disclose the vulnerability until a fix has been released.

Scope

This security policy covers all packages maintained in this monorepo:

  • berlioz/core
  • berlioz/config
  • berlioz/service-container
  • berlioz/event-manager
  • berlioz/router
  • berlioz/http-core
  • berlioz/http-message
  • berlioz/http-client
  • berlioz/cli-core
  • berlioz/mailer
  • berlioz/form
  • berlioz/flash-bag
  • berlioz/html-selector
  • berlioz/queue-manager
  • berlioz/twig-package
  • berlioz/hector-package
  • berlioz/queue-manager-package

Thank you

We appreciate your help in keeping the Berlioz Framework and its users safe.

Learn more about advisories related to BerliozFramework/Berlioz in the GitHub Advisory Database