| Version | Supported |
|---|---|
| 0.1.x | Yes |
Do not disclose exploitable defects publicly before maintainers can review them. Open a private GitHub Security Advisory in the repository that hosts Q-SECAT. Include affected version, impact, reproduction in a safe environment, and proposed remediation when available.
Reports may cover the CLI, schemas, catalog integrity, unsafe test language, dependency risks or documentation that could cause a materially incorrect assessment.
Q-SECAT itself does not authorize testing of third-party systems. Evidence submitted to the project must be sanitized and lawfully obtained.