Only the latest released version of Razin receives security fixes. Older versions are not patched or backported.
| Version | Supported |
|---|---|
| Latest | Yes |
| Older | No |
If you discover a security vulnerability, please report it privately:
Email: security-razin@theinfosecguy.xyz
Include as much detail as possible:
- Description of the vulnerability
- Steps to reproduce
- Affected version(s)
- Potential impact
Do not open a public GitHub issue for security vulnerabilities.
- Acknowledgement: within 7 business days of report
- Triage and initial update: within 7 to 14 business days of report
These are targets, not guarantees. Complex issues may take longer. We will keep you informed of progress.
We follow coordinated disclosure. We will work with you on a timeline for public disclosure after a fix is available.