Skip to content

Security: koo-projects/loomio

Security

SECURITY.md

Security policy

Supported versions

Security fixes are released for the current version of Loomio. We do not provide security updates for older release series. Self-hosted Loomio administrators should keep their installation up to date, follow the upgrade guide, and review the release notes for security information.

To receive notifications when new versions are published, watch this repository on GitHub and select Custom, then Releases. Published security advisories are available on the repository's Security Advisories page.

Reporting a vulnerability

Do not report suspected security vulnerabilities in a public GitHub issue or discussion.

Report a vulnerability privately through GitHub Security Advisories. Include the following information where possible:

  • The affected Loomio version or commit
  • The configuration and permissions required to reproduce the issue
  • Steps to reproduce the issue or a proof of concept
  • The impact you believe the issue could have
  • Any suggested mitigation or fix

We will use the private advisory to discuss the report, assess its impact, and coordinate a fix and disclosure with you. Please keep the vulnerability and the advisory confidential until we have published the advisory or agreed on a disclosure date.

If the report is accepted, we will publish a GitHub Security Advisory when a fix is available. The advisory will identify affected and patched versions and credit the reporter unless they prefer not to be named.

There aren't any published security advisories