| Version | Supported |
|---|---|
| 3.x (latest release) | ✅ |
| < 3.0 | ❌ |
If a vulnerability affects older versions, the fix will land in the latest release. Upgrading is the supported remediation path.
Please do not open a public issue for security vulnerabilities.
Report privately via GitHub's private vulnerability reporting ("Report a vulnerability" in the Security tab of this repository).
You can expect:
- An acknowledgment within 48 hours
- An assessment and severity classification within 7 days
- A coordinated fix and disclosure if the report is accepted, with credit in the release notes unless you prefer otherwise
Given the nature of this project (an OTA update server delivering code to end-user devices), reports affecting update integrity, authentication, or code signing are treated with the highest priority.