Bulwark is pre-1.0; security fixes are applied to the latest main and the
most recent tagged release. Older tags are not maintained.
Please report suspected vulnerabilities privately via GitHub's "Report a vulnerability" button under this repository's Security tab (Private Vulnerability Reporting). Do not open a public issue for security matters.
We aim to acknowledge a report within 5 business days and to provide a remediation timeline after triage. Coordinated disclosure is appreciated; please give us a reasonable window to ship a fix before any public write-up.
This policy covers the Bulwark source in this repository. Vulnerabilities in third-party dependencies should be reported upstream; if a dependency issue affects Bulwark, we will track and pin/patch it here.