Security fixes are applied to the latest released MINOR version of the current MAJOR line. When a new MAJOR is released, the previous MAJOR receives security fixes for a defined transition period (stated in the release notes).
| Version | Supported |
|---|---|
| Latest MINOR of current MAJOR | ✅ Yes |
| Previous MAJOR (transition period) | ✅ Yes (see release notes) |
| Older versions | ❌ No |
Do not open a public GitHub issue for security vulnerabilities.
To report a vulnerability, please use one of the following channels:
qavo-be or qavo-fe). This is the preferred channel.pom.xml / package.json. Encrypt your message with the maintainer’s public GPG key if the content is sensitive.Please include:
This policy covers the Qavo platform modules (qavo-be, qavo-fe) and the documentation in this repository. It does not cover applications built on top of Qavo — those are the responsibility of their respective maintainers.
Qavo is built with AI assistance. The maintainers are aware that AI-generated code can contain subtle security issues and apply extra diligence in review, especially in security-sensitive areas (authentication, authorization, cryptography, input validation). If you find a vulnerability that appears to stem from AI-generated code, please report it through this process like any other — the origin of the code does not affect the seriousness with which it is treated.