Security fixes are prioritized for the latest stable release and the current
main branch. Older releases are not backported automatically.
| Version | Supported |
|---|---|
| Latest stable release | Yes |
main |
Yes |
| Older releases | No |
For production use, install the latest release published on the Releases page.
Please do not report security vulnerabilities in a public issue, discussion, or pull request.
Use GitHub's private vulnerability reporting form:
https://github.com/C76GN/gf-framework/security/advisories/new
If private reporting is unavailable, email
cl7o6dgyn@gmail.com with the subject
[GF Security] Confidential vulnerability report. Please do not include
secrets or a full exploit in the subject line.
Include, where possible:
- the affected version or commit;
- a concise description of the impact;
- reproduction steps or a minimal proof of concept;
- the affected component and configuration; and
- any suggested mitigation.
Please redact credentials, private source code, personal data, and unredacted production logs. The maintainers will acknowledge valid reports and coordinate follow-up through GitHub.