Security fixes are issued for the following lines:
| Version | Supported |
|---|---|
| 4.x | ✅ |
| 3.x | ✅ |
| < 3.0 | ❌ |
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Use GitHub's private vulnerability reporting:
- Open https://github.com/quartznet/quartznet/security/advisories/new
- Provide a clear description, the affected version(s), and a proof of concept or reproduction steps
- Indicate the impact (e.g. data loss, deadlock, information disclosure, remote code execution)
- Acknowledgment of your report within a few business days.
- An initial assessment and, where applicable, a coordinated fix and release plan.
- Public disclosure via a GitHub Security Advisory once a fix is available, with credit to you (unless you prefer to remain anonymous).
If you do not receive a response within a reasonable time, you can ping the maintainers in the advisory thread or via the public discussion forums for a status check — but please continue to keep technical details private.