The following versions of Rvg are currently receiving security updates:
| Version | Supported |
|---|---|
| latest | ✅ |
| < latest | ❌ |
Update this table with real version numbers once you have official releases (e.g. 1.x, 2.x).
If you discover a security vulnerability in Rvg, please do not open a public GitHub issue.
Instead, report it privately through the following channel:
- Telegram: @codebox
Please contact us directly and privately via Telegram rather than posting details publicly.
Please include as much of the following information as possible:
- A description of the vulnerability and its potential impact
- Steps to reproduce the issue (proof-of-concept code, if available)
- The version/commit of Rvg affected
- Any suggested fix or mitigation, if you have one
- We aim to acknowledge new reports within 48–72 hours.
- We will investigate and confirm the issue, then work on a fix.
- Once a fix is ready, we will coordinate a release and, if appropriate, publish a security advisory.
- We ask that you give us a reasonable amount of time to address the issue before disclosing it publicly (responsible disclosure).
This policy covers the Rvg source code in this repository. Issues in third-party dependencies should be reported to their respective maintainers, though we appreciate being notified as well.
We're happy to credit security researchers who responsibly report valid vulnerabilities, unless they prefer to remain anonymous.
Thank you for helping keep Rvg and its users safe.