Skip to content

Security: underctrl-io/commandkit

Security

SECURITY.md

Security Policy

Supported Versions

The following table lists the versions of our project that are currently supported with security updates.

Version Supported
1.x
< 1.0

We strongly recommend keeping your installation up to date with the latest stable release to ensure you receive all security patches and improvements.

Reporting a Vulnerability

If you discover a security vulnerability, we greatly appreciate your help in responsibly disclosing it.

To report a potential issue, please contact our security team at:

📧 [email protected]

When reporting, please include as much detail as possible:

  • Steps to reproduce the vulnerability
  • Potential impact or risk level
  • Any relevant code snippets or configurations

You can expect:

  • Initial acknowledgment within 48 hours
  • Regular updates (at least weekly) on the status of your report
  • Notification once the issue is verified, mitigated, or resolved

If the vulnerability is confirmed, we will prioritize it for patching and release a fix as soon as possible. If it is not accepted as a valid security issue, we will explain our reasoning clearly.

Thank you for helping us keep our project and community secure.

Learn more about advisories related to underctrl-io/commandkit in the GitHub Advisory Database