We actively monitor and provide security patches for the following versions of cgi-core:
| Version | Supported |
|---|---|
| >= 1.4.0 | ✅ |
| < 1.4.0 | ❌ |
Please do not open a public GitHub issue or pull request to report a security vulnerability.
If you discover a security vulnerability within cgi-core, please report it privately using one of the following methods:
- GitHub Security Advisory (Preferred): Go to the "Security" tab of this repository, click on "Vulnerabilities", and select "Report a vulnerability".
- Email: Contact the maintainer directly at laurent.fortin@gmail.com.
- A detailed description of the potential vulnerability.
- A minimal working example (PoC) or steps to reproduce the issue.
- The estimated impact on the runtime environment.
We take security very seriously. We will acknowledge receipt of your report within 72 hours and work with you to coordinate a patch before any public disclosure.