We take the security of mus-go seriously. If you believe you have found a security vulnerability, please report it to us following the guidelines below.
We provide security updates for the following versions of mus-go:
| Version | Supported |
|---|---|
| v0.10.x | ✅ |
| < v0.10 | ❌ |
We recommend all users stay on the latest minor version to receive the most up-to-date security patches.
Please do not report security vulnerabilities through public GitHub issues.
Instead, please use the GitHub Private Vulnerability Reporting feature:
- Navigate to the mus-go repository on GitHub.
- Click on the Security and quality tab.
- Click on Report a vulnerability to open a private advisory.
Using this feature allows us to communicate with you privately, resolve the issue, and coordinate a public disclosure once a fix is available.
- We will acknowledge receipt of your report within 48 hours.
- We will provide a preliminary assessment of the issue and keep you informed of our progress.
- Once a fix is verified, we will release a new version and publish a security advisory to inform the community.
Thank you for helping keep mus-go secure!