Security fixes are currently provided for the latest minor release only.
| Version | Supported |
|---|---|
| 0.2.x | Yes |
| < 0.2 | No |
Please do not open a public issue for security vulnerabilities.
Report privately via:
- GitHub Security Advisories (preferred):
https://github.com/peter941221/CICost/security/advisories/new - Fallback contact: open an issue titled
SECURITY: private report requestedwithout sensitive details.
When reporting, include:
- Affected command/module and version.
- Reproduction steps or proof of concept.
- Impact assessment and suggested remediation if known.
- Initial triage response: within 72 hours.
- Confirmed vulnerability status update: within 7 days.
- Fix release target: as soon as practical based on severity.