| Version | Supported |
|---|---|
| latest | Yes |
| < latest | No |
We only provide security patches for the latest release. We recommend always running the most recent version.
We take security seriously. If you discover a vulnerability in mautrix-mattermost, please report it responsibly.
Do not open a public GitHub issue for security vulnerabilities.
Instead, please use GitHub Security Advisories (preferred): Go to the Security Advisories page and click "Report a vulnerability".
- Description of the vulnerability
- Steps to reproduce
- Affected versions
- Potential impact
- Suggested fix (if any)
- Acknowledgment: Within 48 hours of receipt
- Initial Assessment: Within 5 business days
- Fix Timeline: Depends on severity
- Critical: Patch within 7 days
- High: Patch within 14 days
- Medium/Low: Included in next scheduled release
This security policy covers the mautrix-mattermost bridge itself. Issues in upstream dependencies should be reported to their respective maintainers:
- Mattermost: Mattermost Responsible Disclosure
- Matrix/Synapse: Matrix Security
- mautrix/go: mautrix GitHub
We follow coordinated disclosure. We will work with you to understand the issue and agree on a disclosure timeline before any public announcement.