How to report a vulnerability in MQDB and which versions receive fixes.
Only the latest released version of each crate receives security fixes. Current versions:
| Crate | Version |
|---|---|
| mqdb-cli | 0.8.13 |
| mqdb-core | 0.7.3 |
| mqdb-cluster | 0.3.7 |
| mqdb-agent | 0.8.10 |
| mqdb-wasm | 0.3.4 |
| mqdb-vault | 0.1.2 |
Do not open a public issue for security vulnerabilities.
Email contact@laboverwire.ca with:
- Description of the vulnerability
- Steps to reproduce
- Affected versions
- Impact assessment (if known)
- Acknowledgment: within 48 hours
- Initial assessment: within 1 week
- Fix or mitigation: depends on severity
We follow coordinated disclosure. Vulnerabilities will be disclosed publicly after a fix is available and users have had reasonable time to update.