Security Policy

This is the security policy for the Perl Docbook::Convert distribution.

This policy was updated on 2026-09-26.

Reporting a Security Vulnerability

Please report security vulnerabilities via GitHub private vulnerability reporting:

https://github.com/aspeer/pm-Docbook-Convert/security/advisories/new

If you cannot use GitHub, report the issue privately to Andrew Speer andrew.speer@isolutions.com.au. Do not report vulnerabilities through public issues, pull requests, mailing lists, social media, or other public forums.

Include the affected version, Perl version and operating system when relevant, reproduction steps or a test case, relevant logs or code, whether exploitation is known, and whether you want public credit. Do not include credentials or other sensitive information unless strictly necessary and safe to share.

For triage or CVE coordination, you may also contact the CPAN Security Group at cpan-security@security.metacpan.org. For a compromised PAUSE account, contact pause-admin@perl.org.

Supported Versions

Security fixes are normally made against the latest release on CPAN. Older releases are not routinely supported unless a backport is practical and necessary. Check CPAN and the public GitHub repository for the latest release.

Handling, Disclosure, and Scope

The volunteer maintainer will aim to acknowledge and investigate reports as soon as practical, coordinate a fix, and arrange disclosure where appropriate. Do not disclose vulnerability details or mitigations publicly before an agreed date or publication by the maintainer or CPANSec.

This policy covers vulnerabilities in this distribution. Use the public GitHub issue tracker for installation problems, ordinary bugs, feature requests, and documentation issues.

This policy follows CPAN Security Group guidance: https://security.metacpan.org/docs/guides/security-policy-for-authors.html