Security updates are provided for the latest minor release line. Users should install the latest available patch release within that line.
| Version | Supported |
|---|---|
| 0.9.x | ✅ |
| < 0.9 | ❌ |
Please report suspected security vulnerabilities privately by emailing
package-management@eqtylab.io with the
subject [SECURITY] eqty-sdk-r vulnerability.
Do not open a public GitHub issue or disclose the vulnerability publicly until a fix or mitigation has been released. Please include as much of the following information as possible:
- the affected package version and component;
- a description of the vulnerability and its potential impact;
- steps or a minimal example that reproduces the issue;
- any known conditions required to exploit it;
- suggested mitigations or fixes, if available; and
- whether you would like to be credited in an advisory.
Do not include credentials, private keys, access tokens, personal data, or other sensitive data in the report or reproduction files. We may ask you to use a more secure transfer method if sensitive diagnostic material is needed.
You can expect:
- acknowledgement within three business days;
- an initial assessment or status update within seven business days; and
- updates at least every ten business days while an accepted report remains unresolved.
If the report is accepted, we will investigate its impact, develop and test a fix or mitigation, and coordinate disclosure with you. When appropriate, we will publish a security advisory and credit the reporter according to their preference. We aim to resolve accepted reports within 90 days, although the timeline may change with the severity and complexity of the issue.
If the report is declined, we will explain why it is not considered a security vulnerability. With your agreement, we may suggest filing a sanitized public issue when the report describes a regular defect or enhancement.
Thank you for helping keep eqty.sdk.r and its users safe.