Skip to content

Security: cucumber-rs/cucumber

SECURITY.md

Security Policy

Security policy of cucumber crate (and its cucumber-codegen sub-crate).

Supported versions

Before going 1.0, the cucumber crate maintains only the most recent minor release.

Reporting a vulnerability

Security is of the highest importance and all security vulnerabilities or suspected security vulnerabilities should be reported to this project privately, to minimize attacks against current users of cucumber crate before they are fixed. Vulnerabilities will be investigated and patched on the next patch (or minor) release as soon as possible. This information could be kept entirely internal to the project.

Private disclosure process

WARNING: Do not file public issues on GitHub for security vulnerabilities.

To report a vulnerability or a security-related issue, please use GitHub private vulnerability reporting on the Security Advisories page and fill the vulnerability details. It will be addressed within a week, including a detailed plan to investigate the issue and any potential workarounds to perform in the meantime. Do not report non-security-impacting bugs through this channel, use GitHub issues instead.

Public disclosure process

Project maintainers publish a public advisory to the community via GitHub.

There aren’t any published security advisories