Only the latest major version released currently receives security updates. We strongly recommend upgrading to the newest release if you are on an older version.
If you discover a security vulnerability, please do not open a public issue. Instead, get in touch by sending an email to security@holodeck-b2b.org.
To help us triage and resolve the issue quickly, please include:
- The specific product and version(s) of the software affected.
- A clear description of the vulnerability and its potential impact.
- Step-by-step instructions to reproduce the issue (including proof-of-concept code, if available).
We will respond within 72 hours and aim to fix critical issues as soon as possible. If the vulnerability is assessed to be actively exploited or poses a severe, unmitigated risk, we will notify the appropriate authorities (ENISA / CSIRT) within the legally required timelines.
Security advisories are published in the GitHub Security Advisories section of this repository.
Critical fixes are announced via GitHub Releases (with a [SECURITY] tag).