| Version | Supported |
|---|---|
| 0.3.x | Yes |
| < 0.3 | No |
If you discover a security vulnerability, please report it responsibly:
- Do NOT open a public issue
- Email: leandropatodo@gmail.com
- Include:
- Description of the vulnerability
- Steps to reproduce
- Impact assessment
- Suggested fix (if any)
You will receive a response within 48 hours. Critical issues will be patched within 7 days.
- All SQL queries use parameterized bindings (sqlx)
- No user input in shell commands
- Secrets via environment variables only
- UTF-8 safe string truncation
- GDPR Right to Erasure (
cuba_forget) - 0 active CVEs (audited 2026-03-28)