| Version | Supported |
|---|---|
| 1.0.x | ✅ |
If you discover a security vulnerability in Cadence, please report it by emailing seetmadilog@gmail.com (or open a private security advisory on GitHub).
Please include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Initial response: Within 48 hours
- Status update: Within 7 days
- Resolution target: Within 30 days for critical issues
We follow responsible disclosure. Please do not publicly disclose the vulnerability until we have released a fix and notified users.
When using Cadence in production:
- Keep updated - Always use the latest stable version
- Monitor metrics - Track rate limiter rejections for anomalies
- Set appropriate limits - Configure capacity based on your application requirements
- Validate inputs - Ensure user identifiers for per-user limiting are properly sanitized