GMA Administration is independently versioned. Security fixes are made on dev and included in the next tagged release. During the pre-1.0 period, only the latest tagged release and dev receive fixes.
| Version | Supported |
|---|---|
dev |
Pre-release security fixes |
v0.2.0 |
Yes |
| Older releases | No |
Use GitHub's private vulnerability reporting form. Do not open a public issue for an undisclosed vulnerability and do not include credentials, personal data, payment data, identity documents, or third-party confidential data in a report.
Include the affected commit or release, impact, reproducible steps or a minimal proof of concept, and any known mitigation. A composition issue may also be reported to GMA-Skeleton or the owning product repository; maintainers will route it privately.
We aim to acknowledge a complete report within three business days and provide an initial assessment within seven business days. These are response targets, not a contractual support SLA. Please coordinate public disclosure until a fix or mitigation is available.
There is currently no paid bug-bounty programme. Good-faith, non-destructive research against systems and data you own is welcome; denial of service, social engineering, persistence, and access to another person's data are out of scope.