Security fixes are made for the current minor release. Users should update to the latest patch in that minor. Older minors and prereleases are not supported unless a release note says otherwise.
Use GitHub private vulnerability reporting for this repository. Open the repository's Security tab, choose "Report a vulnerability," and create a private security advisory. Do not open a public issue for a suspected vulnerability.
Include the affected version, impact, reproduction steps, and the smallest useful proof of concept. Output from muster doctor can help, but redact usernames, home and project paths, repository names, connector names, tokens, and other private configuration before attaching it.
We aim to acknowledge a report within three business days and provide an initial assessment within ten business days. Complex reports may take longer, but we will keep the reporter informed.
Please keep the report under embargo while we investigate and prepare a fix. We will coordinate disclosure timing and credit with the reporter. If we cannot agree on a date, allow at least 90 days from acknowledgement before public disclosure unless active exploitation requires a shorter timeline.