| Version | Supported |
|---|---|
| latest | ✅ |
Only the latest published release receives security fixes.
Please do not open a public GitHub issue for security vulnerabilities.
Instead, report vulnerabilities through one of:
- GitHub Security Advisories (preferred): Report a vulnerability
- Email: mail@forrestblade.com
- Description of the vulnerability
- Steps to reproduce
- Affected versions
- Potential impact
- Acknowledgment within 48 hours
- Initial assessment within 1 week
- Fix timeline communicated after assessment
- Credit in the release notes (unless you prefer anonymity)
- Keep Valence and its dependencies up to date
- Never commit
.envfiles or database credentials to version control - Use environment variables for all secrets
- Enable PostgreSQL SSL in production