Security Policy
Reporting a vulnerability
Please report security vulnerabilities privately by email to Joshua S. Day at hax@cpan.org. Do not open a public GitHub issue for a suspected security vulnerability.
Include enough detail to reproduce and assess the issue, including affected versions, configuration, impact, and a minimal reproducer when possible.
Supported versions
For the current pre-1.0 line, security fixes are applied to the latest released version and the current development line. Older pre-1.0 releases may not receive backports unless a security issue warrants one.
Installation and usage issues
Ordinary bugs, build failures, documentation problems, and non-security usage questions should be reported through the GitHub issue tracker.
Workflow
Security reports will be reviewed privately. Confirmed vulnerabilities will be fixed before public disclosure when practical, and release notes will identify security-relevant fixes without exposing users unnecessarily before a fix is available.