Skip to content

Security: tyler-technologies-oss/forge

SECURITY.md

Security Policy

Supported Versions

Version Supported
3.x ✅ Active
< 3.0 ❌ End of life

Reporting a Vulnerability

If you discover a security vulnerability in Tyler Forge, please report it through GitHub's private vulnerability reporting.

Please do not:

  • Open public issues for security vulnerabilities
  • Disclose vulnerabilities publicly before they are addressed

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fixes (optional)

Response Timeline

  • Initial response: Within 5 business days
  • Status update: Within 10 business days
  • Resolution target: Depends on severity

Disclosure

We follow coordinated disclosure. Once a fix is released, we will:

  1. Publish a security advisory
  2. Credit the reporter (unless they prefer anonymity)
  3. Release patched versions

Thank you for helping keep Tyler Forge secure.

There aren’t any published security advisories