Security policy

Found a vulnerability? Report it privately

Please don't open a public issue for security problems. Every TerraFluent repository accepts private reports through GitHub Security Advisories.

How to report

Use GitHub's private vulnerability reporting on the repository of the affected package — Security → Report a vulnerability, or go there directly:

A useful report describes the affected package and version, the impact, and ideally a proof-of-concept. You'll get an acknowledgement in the advisory thread, and credit in the fix release unless you prefer otherwise.

Supported versions

Security fixes target the latest released version of each package — currently TerraFluent.Pdf.Reporting 2.0.2, TerraFluent.Html.Reporting 1.1.1, and TerraFluent.Docx.Reporting 1.3.0. Older versions do not receive backported fixes; upgrading is free and, within a major version, source compatible.

Scope worth knowing about

Repository security policies

Per-repository SECURITY.md files: