Security policy
Please don't report security issues in public issues, discussions, or pull requests.
Reporting a vulnerability
On the Clinimatix/Caravel repository, open Security → Report a vulnerability if that option is available. If it isn't, contact a maintainer through an established private channel to arrange a report. Do not post vulnerability details publicly or guess a contact address.
Please include:
- the affected version or commit, your .NET SDK version, and your OS
- a minimal, made-up example that reproduces the problem
- what you expected to be protected, and what actually happened
- any workaround you know of
Send only what's needed to reproduce the issue. Please don't include real personal data, secrets, live connection strings or unredacted logs.
Keep the details private, including any fix that would reveal them, until a maintainer has coordinated disclosure with you.
What to expect
Caravel is prerelease software, and milestone builds and release candidates are meant for evaluation. There's no guaranteed response time. Maintainers assess severity and affected versions, and security fixes ship with a regression test in a new release. Older prereleases generally aren't patched; upgrade to the latest release.
Supported versions
| Version | Supported |
|---|---|
| Latest milestone or release candidate | Yes |
| Earlier prereleases | No |
