| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Security fixes go into the latest release. There are no long-term support branches: if you are on an older version, upgrading is the fix.
| Version | Supported |
|---|---|
| Latest release | ✅ |
| Anything earlier | ❌ |
Report privately through GitHub, using Report a vulnerability on the Security tab. That opens an advisory visible only to you and the maintainers.
Please do not open a public issue for something you believe is exploitable.
Include what you have: the version (vale --version), the platform, and a configuration and input file that reproduce it. A minimal reproduction is worth more than a description.
You can expect an acknowledgement within a week. If a report is accepted, the fix ships in the next release and the advisory is published with credit unless you would rather not be named. If it is declined, you will get the reasoning, and you are free to disclose it publicly at that point.
Vale reads configuration, styles, and documents that a project supplies, and vale sync downloads packages that configuration names. Anything letting those inputs escape their intended effect is in scope, including:
| Back | FazBrowse Home | New Git URL |