| Version | Supported |
|---|---|
| 3.x | Yes |
| < 3.0 | No |
If you discover a security vulnerability within the Berlioz Framework, please do not open a public issue.
Instead, please use GitHub's built-in vulnerability reporting:
- Go to the Security tab of this repository.
- Click "Report a vulnerability".
- Fill in the advisory form with as much detail as possible.
When reporting, please include:
- A clear description of the vulnerability.
- Steps to reproduce the issue or a proof of concept.
- The affected package(s) and version(s).
- The potential impact of the vulnerability.
- You will receive an acknowledgment within 48 hours.
- We will collaborate with you directly in the GitHub Security Advisory to understand and verify the issue.
- A fix will be prepared and released as soon as possible, depending on the severity.
- You will be credited in the release notes (unless you prefer to remain anonymous).
We follow a coordinated disclosure process:
- The vulnerability is reported privately.
- We confirm the issue and develop a fix.
- A new release is published with the fix.
- The vulnerability is publicly disclosed after the fix is available.
We ask that you do not publicly disclose the vulnerability until a fix has been released.
This security policy covers all packages maintained in this monorepo:
berlioz/coreberlioz/configberlioz/service-containerberlioz/event-managerberlioz/routerberlioz/http-coreberlioz/http-messageberlioz/http-clientberlioz/cli-coreberlioz/mailerberlioz/formberlioz/flash-bagberlioz/html-selectorberlioz/queue-managerberlioz/twig-packageberlioz/hector-packageberlioz/queue-manager-package
We appreciate your help in keeping the Berlioz Framework and its users safe.