Skip to content

Security Vulnerability Reporting ​

The DevDiff team takes the security of our software seriously. If you believe you have discovered a security vulnerability in any DevDiff package, please report it responsibly following the instructions below.


Responsible Disclosure Channel ​

CAUTION

Do NOT file public GitHub Issues for unpatched security vulnerabilities.

Please report security vulnerabilities through our private advisory channel:


Response SLA ​

  • Initial Response: Within 48 hours.
  • Triage & Impact Assessment: Within 5 business days.
  • Patch Release: High severity vulnerabilities will receive an expedited patch release within 7 business days.