The latest released version of Release Hub receives security fixes. Older versions are not actively maintained.
Please do not open a public GitHub issue for security vulnerabilities.
Instead, report suspected vulnerabilities privately using GitHub's Private Security Advisory feature on this repository.
When reporting, please include:
- A description of the vulnerability and its impact
- Steps to reproduce, including any proof-of-concept code
- Affected version(s)
- Any suggested mitigation, if known
You can expect an initial response acknowledging your report. We will work with you to validate the issue, develop a fix, and coordinate disclosure.
This policy covers the Release Hub Azure DevOps extension source code in this repository. Vulnerabilities in upstream dependencies should be reported to the respective projects.