Skip to content

Security: konfirm/geojson

Security

SECURITY.md

Security

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Use GitHub's private vulnerability reporting instead. This keeps the details confidential until a fix is ready.

If you prefer email, send a report to geojson@konfirm.eu with the subject line [geojson] Security vulnerability.

What to include

  • A description of the vulnerability and its potential impact
  • The affected version(s)
  • Steps to reproduce or a minimal proof-of-concept
  • Any suggested mitigations, if you have them

What to expect

  • Acknowledgement within 72 hours
  • A fix or mitigation plan within 14 days for confirmed issues, depending on severity and complexity
  • Credit in the release notes unless you prefer to stay anonymous

Supported versions

Only the latest release receives security fixes. If you are on an older version, upgrade first before reporting — the issue may already be resolved.

Disclosure policy

This project follows coordinated disclosure: details are kept private until a patch is published, after which the advisory is made public.

There aren't any published security advisories