Skip to content

Security: digital-dumbo/jragas

Security

SECURITY.md

Security Policy

Reporting Security Issues

We take the security of Ragas Java seriously. If you discover a security vulnerability in this project, please report it privately. Do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

To report a vulnerability, email founders@vibrantlabs.com. Please include as much information as possible:

  • Type of issue (for example, SSRF, deserialization, injection)
  • Affected versions
  • Affected files or modules
  • Location in code (tag, branch, commit, or URL)
  • Configuration details required to reproduce
  • Environment (OS, Java version)
  • Reproduction steps
  • Proof-of-concept or exploit code, if possible
  • Impact assessment and suggested mitigation

Supported Versions

The following versions of Ragas Java are currently supported with security updates:

Version Supported
0.1.x Yes
< 0.1.x No

Security Update Policy

Upon receiving a security report, we will:

  1. Acknowledge receipt within 48 hours.
  2. Investigate and verify the issue.
  3. Develop a fix and prepare a release.
  4. Coordinate with the reporter to validate the fix.
  5. Release the fix and update all affected parties.

We aim to address critical issues within 7 days of disclosure.

Preferred Language

We prefer all communications to be in English.

Policy

We follow the principle of Coordinated Vulnerability Disclosure.

References

  • GitHub's Guide to Reporting Security Vulnerabilities
  • Open Source Security Foundation (OpenSSF) Best Practices

This policy is subject to change without notice. Please refer to the latest version in this repository.

There aren't any published security advisories