Please report suspected vulnerabilities privately through GitHub Private Vulnerability Reporting for this repository. Do not open a public issue for an undisclosed vulnerability.
Before Laghu's first published release, main is the supported version. After releases begin, the supported versions are main and the latest published MAJOR.MINOR release series. Older release series are unsupported.
Maintainers coordinate confirmed vulnerabilities through private GitHub Security Advisories. We acknowledge and investigate reports, but this policy does not define separate numeric service-level deadlines.
For a confirmed vulnerability in supported Laghu code that requires coordinated disclosure or a security release, maintainers request a CVE. Published advisories include affected versions, severity, mitigation, fix, credit, and corrected-release information.
When feasible, confirmed vulnerabilities receive permanent, non-sensitive regression coverage. If regression automation is infeasible, the advisory or fixing pull request records the technical rationale.
Dependency CVEs are evaluated for reachability, exploitability, exposure, severity, fix availability, upgrade risk, and compensating controls. They are not blindly accepted or ignored.