release-kit 0.3.14

A canonical release workflow: a technology-agnostic method, per-technology bindings, and the rk CLI that lands and serves them.
Documentation
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
# Security policy

## Report a vulnerability

Please report a suspected vulnerability through [this project's private vulnerability reporting form](https://github.com/gubasso/release-kit/security/advisories/new). Sign in to GitHub to use the form. This channel is available for public repositories after private reporting is enabled. If it is unavailable, contact a maintainer through an existing private conversation before sending sensitive details.

Do not disclose a vulnerability in a public issue, pull request, discussion, or commit. Keep reproduction material and any proposed fix private while the report is assessed.

Include the affected release, the component involved, the configuration needed to reach it, reproduction steps or a minimal proof of concept, and the security impact you observed. Remove credentials and personal information from attachments. For a dependency advisory, explain how the affected behavior can be reached through this project; a dependency version and a CVE identifier alone do not establish impact.

## Supported releases and disclosure

Start with the latest published release. Older releases receive fixes only where the project explicitly documents a maintained release line. A fix is delivered as a new version; withdrawing an affected version contains exposure and does not repair existing installations.

Reports are handled on a best-effort basis. We ask reporters to coordinate public disclosure while maintainers investigate and prepare a fix. This policy commits to no response or disclosure deadline.