Files
yaml-libyaml/Security.md
2026-05-05 17:55:21 -04:00

938 B

Security Policy

Supported Versions

Version Supported
0.2.x Yes
< 0.2 No

Reporting a Vulnerability

To report a security vulnerability, please use GitHub's private vulnerability reporting.

Do not open a public issue for security vulnerabilities.

We will acknowledge your report within 7 days and aim to release a fix within 30 days for confirmed vulnerabilities.

Coordinated Disclosure

For vulnerabilities affecting downstream consumers (PyYAML, Ruby Psych, etc.), we coordinate disclosure with affected maintainers before public release. Downstream maintainers who want to be included in pre-release notifications can contact the maintainers privately.

Security Advisories

Published advisories are listed on the Security Advisories page.