We release patches for security vulnerabilities in the latest stable version of Roo+. Older versions may receive patches on a best-effort basis.
We take security vulnerabilities seriously. Please report them responsibly.
Do NOT open a public GitHub issue for security vulnerabilities.
Instead, please report via one of these channels:
- GitHub Private Vulnerability Disclosure: Navigate to the repository's "Security" tab and use the "Report a vulnerability" feature.
- Email: Send details to the repository maintainers via your organization's internal security contact.
When reporting, please include:
- A description of the vulnerability
- Steps to reproduce
- Affected versions
- Any potential mitigations you've identified
We will acknowledge receipt within 48 hours and provide an estimated timeline for a fix. Security patches will be fast-tracked through the release process.
We follow a coordinated disclosure process:
- The vulnerability is reported privately
- A fix is prepared and tested
- The fix is released in a new version
- The vulnerability is publicly disclosed after the fix is available