Security fixes are provided for the latest stable Messagevisor Java release line. Upgrade before reporting an issue that may already have been fixed.
Do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting form.
Include the affected artifact and version, impact, reproduction steps, and any suggested mitigation. You should receive an initial response within seven days. We will coordinate investigation, remediation, release timing, and disclosure with the reporter.
This policy covers the Java SDK, modules, CLI, and their handling of Messagevisor datafiles. Vulnerabilities in an application's hosting, repository permissions, or deployment configuration should be reported to that application's owner.