The VM Operator maintainers take security issues seriously. We appreciate your efforts to responsibly disclose your findings.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
To report a vulnerability, please use one of the following private channels:
- GitHub Security Advisories for this repository (preferred). This creates a private discussion with maintainers and lets us coordinate a fix before public disclosure.
Please include as much of the following as you can in your report:
- A description of the vulnerability and its potential impact.
- Steps to reproduce, or a proof-of-concept.
- The affected version(s) or commit(s).
- Any known mitigations.
Maintainers will acknowledge your report, investigate, and work with you on a coordinated disclosure timeline. We will credit reporters in the resulting advisory unless anonymity is requested.
VM Operator does not yet publish a formal support matrix. Security fixes are applied to the main branch; see the project's releases for available versions.