Security policy of cucumber
crate (and its cucumber-codegen
sub-crate).
Before going 1.0
, the cucumber
crate maintains only the most recent minor release.
Security is of the highest importance and all security vulnerabilities or suspected security vulnerabilities should be reported to this project privately, to minimize attacks against current users of cucumber
crate before they are fixed. Vulnerabilities will be investigated and patched on the next patch (or minor) release as soon as possible. This information could be kept entirely internal to the project.
WARNING: Do not file public issues on GitHub for security vulnerabilities.
To report a vulnerability or a security-related issue, please use GitHub private vulnerability reporting on the Security Advisories page and fill the vulnerability details. It will be addressed within a week, including a detailed plan to investigate the issue and any potential workarounds to perform in the meantime. Do not report non-security-impacting bugs through this channel, use GitHub issues instead.
Project maintainers publish a public advisory to the community via GitHub.