Security Policy

This is the security policy for the Perl DBIx-Fast distribution.

Reporting a Vulnerability

Please do not report security issues on public GitHub issues, pull requests or any other public forum.

Use GitHub's private vulnerability reporting: https://github.com/SeHarrys/dbix-fast/security/advisories/new

Include enough information to reproduce the issue (Perl version, DBD driver, minimal code sample, expected vs observed behaviour). Do not include passwords, tokens, or personal data in the report.

If you need help triaging or the issue is being actively exploited, you may also contact the CPAN Security Group (CPANSec) at cpan-security@security.metacpan.org.

Supported Versions

Only the latest released version of DBIx::Fast is supported with security fixes. Only major versions of Perl released in the last ten years are supported, even if DBIx::Fast happens to run on older versions.

Disclosure

The maintainer will acknowledge reports as soon as possible (no guaranteed SLA — this is a volunteer project) and coordinate a fix and public disclosure date with the reporter.

If this policy is more than two years old, check the latest version on CPAN or the git repository.