| Version | Supported |
|---|---|
| Latest 3.x minor | ✅ |
| Earlier 3.x minors | ❌ |
| < 3.0 | ❌ |
Fixes land on the latest 3.x minor; older minors are not backported.
Please do not report security vulnerabilities through public GitHub issues.
Instead, report vulnerabilities via email:
- Email: f@lex.la
- GPG Key:
F57F 85FC 7975 F22B BC3F 2504 9C17 3EB1 B531 AA1F
- Type of vulnerability
- Full paths of affected source files
- Location of affected source code (tag/branch/commit)
- Step-by-step reproduction instructions
- Proof-of-concept or exploit code (if possible)
- Impact assessment
- Initial Response: Within 48 hours
- Status Update: Within 7 days
- Fix Timeline: Depends on severity
Deployment hardening lives in the security reference on the documentation site: the controller's Kubernetes permissions and what they imply, API token scope, network policies, and how to verify the signed container images and Helm chart before deploying them.