This is the freemkv organization's default security policy. It applies to any
freemkv repository that does not ship its own SECURITY.md. Repositories with
their own policy (and their own advisory form) take precedence over this one.
| Version | Supported |
|---|---|
| 1.6.x | Yes |
| < 1.6 | No |
Only the current 1.6.x line receives security fixes.
Report vulnerabilities privately through GitHub Security Advisories on the affected repository: open its Security tab → Advisories → Report a vulnerability. Filing on the repo the issue actually affects ensures the maintainers watching it see the report.
Do not open a public issue for a security report. Include the affected version, steps to reproduce, and the impact you believe the issue has.
You will get an initial response within 7 days.