Security policy

Supported versions

Only the latest release (and main) receives security fixes. Update a server with docker compose pull && docker compose up -d (see INSTALL.md).

Reporting a vulnerability

Please report vulnerabilities privately through GitHub Security Advisories on the repository: metor-com/metor -> Security -> Report a vulnerability (https://github.com/metor-com/metor/security/advisories/new). Do not open a public issue and do not post details in discussions or pull requests before a fix is released. You will get an acknowledgement, and once the report is confirmed, a fix and - if you want one - a mention in the advisory.

Scope

This page is metor-com/metor/blob/main/SECURITY.md in the metor repository, rendered as it is.