Skip to content

Navigation Menu

Sign in
Sign up

Security: laranail/console

SECURITY.md

Security

Supported versions

Version Status
1.x Active support

Security fixes are released on the latest 1.x tag.

Reporting a vulnerability

Please do not open a public GitHub issue for security-sensitive findings. Instead, email security@simtabi.com with:

  • A description of the vulnerability and its impact.
  • Steps to reproduce (proof-of-concept welcome).
  • The affected version(s).

We aim to acknowledge reports within 72 hours and triage within 5 business days. Coordinated disclosure timelines are negotiated per case.

Prefer GitHub private vulnerability reporting when you can: open it from this repository's Security tab. The report arrives attached to the repo with a draft advisory and a CVE request path already in place. Email is the fallback for anyone who would rather not use GitHub.

Supply-chain posture

  • roave/security-advisories (dev-latest) is in require-dev — composer install fails if any registered package has an open advisory.
  • Weekly composer audit (GitHub/Packagist advisory database) runs in CI (.github/workflows/security.yml), failing the build on any advisory.
  • Dependabot updates composer + github-actions weekly with Conventional Commits prefixes.

There aren't any published security advisories

AltStyle によって変換されたページ (->オリジナル) /