Skip to content

Security Vulnerability Reporting

The DevDiff team takes the security of our software seriously. If you believe you have discovered a security vulnerability in any DevDiff package, please report it responsibly following the instructions below.


Responsible Disclosure Channel

CAUTION

Do NOT file public GitHub Issues for unpatched security vulnerabilities.

Please report security vulnerabilities through our private advisory channel:


Response SLA

  • Initial Response: Within 48 hours.
  • Triage & Impact Assessment: Within 5 business days.
  • Patch Release: High severity vulnerabilities will receive an expedited patch release within 7 business days.