| Version | Supported |
|---|---|
| 4.x | ✅️ |
| < 4.0 | ❌ |
Please do not report security vulnerabilities through public GitHub issues.
Instead, please report them privately through GitHub Security Advisories:
- Go to the Security tab of this repository
- Click Report a vulnerability
- Fill out the vulnerability report form
If you cannot use GitHub Security Advisories, email us at security@azion.com.
- A description of the vulnerability and its impact
- Steps to reproduce (proof of concept, affected version, configuration)
- Any known mitigations or workarounds
- Within 3 business days: we acknowledge receipt of your report.
- Within 10 business days: we confirm the issue and share an initial assessment.
- Within 90 days: we aim to release a fix and publish a security advisory.
We follow a coordinated disclosure process: please give us time to release a fix before disclosing the issue publicly. We will credit reporters in the advisory unless you ask us not to.
Published advisories for this project are listed at github.com/aziontech/azion/security/advisories. For more on Azion's security practices, see www.azion.com/en/documentation/.