The following table outlines the supported versions for security updates and patches:
| Version | Supported |
|---|---|
| 3.x | ✅ |
| < 3.0 | ❌ |
We take the security of atha seriously. If you discover a security vulnerability, please report it responsibly through our private reporting channels. Do not disclose security vulnerabilities publicly until they have been addressed and a patch has been released.
- Please report vulnerabilities via GitHub Security Advisories by navigating to the Security tab of this repository and clicking Report a vulnerability.
- Alternatively, you can reach out directly via email to the repository maintainer.
To help us triage and resolve the issue as quickly as possible, please include:
- A detailed description of the vulnerability and its potential impact.
- Step-by-step instructions or proof-of-concept (PoC) code to reproduce the issue safely.
- Any relevant logs, configurations, or system details.
- Acknowledgment: We will acknowledge receipt of your report within 48 hours.
- Investigation: We will investigate the issue, assess its severity, and coordinate a remediation plan.
- Patch & Release: Once a fix is verified, we will release an updated version and publish a security advisory acknowledging your contribution (if desired).
Thank you for helping keep atha secure for everyone.